New fields for SecurityAdvisory GraphQL API
The SecurityAdvisory object in the GraphQL API now includes five new fields, allowing you to read more of the GitHub Advisory Database directly from GraphQL without needing the REST API.
You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API.
The SecurityAdvisory object gained five new fields:
cveId: The advisory’s CVE identifier.sourceCodeLocation: A link to the affected source code relevant to the advisory.githubReviewedAt: When GitHub reviewed the advisory.nvdPublishedAt: When the National Vulnerability Database (NVD) published its record.repositoryAdvisoryUrl: A link to the linked repository security advisory when there is one.
The securityAdvisories query also gained two new filters, severities and isWithdrawn, so you can narrow results on the server instead of downloading everything and filtering it yourself. They work alongside the filters you already use, such as classification, identifier, EPSS, and published or updated since.
This means fewer round trips, one authentication path, and one rate limit budget for integrations that read advisory data. It also makes it easier to build things like severity-based triage feeds, withdrawn advisory audits, and tracking of how quickly advisories move from NVD publication to GitHub review.
These changes are additive and read-only, so your existing queries keep working.
Learn more in the GraphQL API documentation and share your feedback.
The post New fields for SecurityAdvisory GraphQL API appeared first on The GitHub Blog.
Source: original entry ↗
More from GitHub
Follow GitHub to get its new changes in your feed and email digest.
Claude Haiku 5.5 now available in GitHub Copilot
Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.
Purpose-built model for leaked secret detection
GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.
Local sandboxing for GitHub Copilot now generally available
GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.