3 ms·
You can see some of that metadata in the UI for the database: https://github.com/advisories https://github.com/advisories
by greysteil 5y ago
You can see some of that metadata in the UI for the database: https://github.com/advisories https://github.com/advisories
- vcdimension 5y agoOK, thanks. I see it says 6,465 advisories, so I guess you are only storing CVE records that haven't been fixed since the main CVE list currently contains 170804 records. Is this correct?
- greysteil 5y agoThe 6,465 is curated advisories that apply to open source packages in the ecosystems listed. NVD’s 170,804 is all CVEs issued, many of which (the vast majority) don’t apply to open source packages. (Not trying to claim the GitHub Advisory Database is perfectly complete - it’s not, and achieving that is part of why we’ve opened it up to community contributions. Just that the comparison with everything in the NVD isn’t apples to apples - the databases have different scopes.)