3 ms·
https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/ https://github.blog/s
by jamietanna 1mo ago
https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/ https://github.blog/security/supply-chain-security/inside-th... goes into it more
As mentioned by another commenter, they intentionally have a human reviewer in the process before a GitHub Security Advisory (GHSA) becomes "official" post-publish
(this is separate to getting CVE ID assigned, if wanted)