ctipilot.ch

GitHub Advisory Database

github-advisory · B · active

https://github.com/advisories

vulnslang: enfetch failures: 0quiet periods: 0last fetch: 2026-07-14

GitHub-maintained advisory database — high-volume, machine-readable open-source ecosystem advisories (added 2026-05-08). 2026-05-08 audit: WebFetch returned 5 advisories all 2026-05-07 (rust-openssl, utcp-http, netbox, etc.). For per-ecosystem filtering use /advisories?type=...&query=...; for GraphQL / API see https://docs.github.com/en/graphql/reference/objects#securityadvisory. Candidate — promote to active after 3 runs. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://github.com/advisories (listing, dated GHSA items) then webfetch https://github.com/advisories/<GHSA-ID> for affected packages/CVE/severity/CWE. AVOID: Nothing to avoid for browsing; for programmatic/per-ecosystem filtering use /advisories?type=...&query=... or the GraphQL securityAdvisory API.. | 2026-07-05 root-cause + recipe fix: the 403 is NOT a browser-UA / anti-bot refusal — github.com AND api.github.com are blocked by the agent egress proxy itself (each session is bound to its configured repository; every other github.com path returns HTTP 403 with body `sessions are bound to their configured repositories`). No UA / header / Sec-CH-UA set recovers it (re-confirmed across chrome/firefox/googlebot/curl/minimal), and it behaves identically in the routine container. FETCH → bridge (OSV.dev, the reachable full mirror of the GitHub Advisory Database — every GHSA id, aliased to its CVE): `python3 tools/fetch_source.py osv query <ecosystem> <package> [version]` for advisories affecting a watchlist package (ecosystem ∈ npm|PyPI|Go|Maven|crates.io|NuGet|RubyGems|Packagist…), and `python3 tools/fetch_source.py osv vuln <GHSA-or-CVE>` to drill one advisory. fetch_method flipped webfetch→bridge; github.com/advisories stays the human citation URL. | 2026-07-05 admiralty audit: B — curated/reviewed advisory DB, canonical for GHSA namespace + some original research (mixed with CVE mirror); live, keep active.

Cited in 60 entries

Citation cadence

Citation days per ISO week (11 weeks of coverage span, total 38).