Skip to content

Comment on GitHub’s database of security advisories is now open sourceparent

Comments

Oh good question. I can't answer this one as authoritatively as I'd like - I'll double check with the team next week.

One thing to note is that the full CVSS 3.1 string is included in the database as assessed by NIST. The severity displayed by GitHub is stored as a "database specific" field, so it looks like we're trying to be explicit about the existence of multiple perspectives on severity (one of which is our own), but that we could do more to make that clear.

https://github.com/github/advisory-database/blob/main/adviso...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.