Tech article
New fields for SecurityAdvisory GraphQL API
Publisher description: You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API.
github | Oct 2, 2026 | Allison
Automated excerpt
sourceCodeLocation: A link to the affected source code relevant to the advisory. githubReviewedAt: When GitHub reviewed the advisory. nvdPublishedAt: When the National Vulnerability Database (NVD) published its record. repositoryAdvisoryUrl: A link to the linked repository security advisory when there is one. This means fewer round trips, one authentication path, and one rate limit budget for integrations that read advisory data. It also makes it easier to build things like severity-based triage feeds, withdrawn advisory audits, and tracking of how quickly advisories move from NVD publication to GitHub review.
Selected automatically from source text; not independently written or fact-checked. Read the original for full context.