Skip to main content

GitHub Advisory Database

Threat Intelligence

The GitHub Advisory Database connector syncs the global GitHub Advisory Database into Brinqa. It covers every GitHub-reviewed security advisory (GHSA) across all supported ecosystems — npm, pip, Maven, NuGet, RubyGems, Go, Composer, Rust, Erlang, Pub, Swift and GitHub Actions — and can optionally include unreviewed and malware advisories.

Each advisory is synced with its identifiers (GHSA, CVE), severity, CVSS v3 and v4 scoring, EPSS probability and percentile, CWE weaknesses, references and lifecycle dates. Every affected package is synced as its own record with its vulnerable version ranges, first patched versions and vulnerable functions, linked back to the advisory.

Use it as an advisory catalog to enrich Dependabot, Snyk and other open-source (SCA) findings with GitHub's severity, EPSS and CWE data, including advisories that are not in the NVD.

This is a public knowledge-base connector: it does not read anything from your own GitHub organizations or repositories. To sync Dependabot, code scanning or secret scanning alerts, use the GitHub connector.

Data retrieved from GitHub Advisory Database​

Connector ObjectRequiredMaps to Data Model
Security AdvisoryYesSecurity Advisory
Vulnerable PackageYesPackage

Model relationships​

note

For detailed steps on how to view the data retrieved from GitHub Advisory Database in the Brinqa Platform, see How to view your data.