New fields for SecurityAdvisory GraphQL API
By Steven Van ·
Five new SecurityAdvisory fields and two new query filters let integrations read advisory data from GraphQL without using the REST API.
The GitHub GraphQL API now exposes more of the GitHub Advisory Database, so integrations no longer need to fall back to the REST API for some advisory data. The SecurityAdvisory object gained five fields, and the securityAdvisories query gained two filters.
The new fields on SecurityAdvisory:
- cveId: the advisory's CVE identifier
- sourceCodeLocation: a link to the affected source code relevant to the advisory
- githubReviewedAt: when GitHub reviewed the advisory
- nvdPublishedAt: when the National Vulnerability Database (NVD) published its record
- repositoryAdvisoryUrl: a link to the linked repository security advisory, when there is one
The two new filters, severities and isWithdrawn, narrow results on the server instead of requiring a full download and local filtering. They work alongside existing filters such as classification, identifier, EPSS, and published or updated since.
GitHub says this means fewer round trips, one authentication path and one rate limit budget for integrations that read advisory data. It suggests uses such as severity-based triage feeds, withdrawn advisory audits, and tracking how quickly advisories move from NVD publication to GitHub review. The changes are additive and read-only, so existing queries keep working.
