GitHub Advisory Database now open to community contributions
Blog post from GitHub
GitHub has opened its Advisory Database to community contributions, enabling security researchers, academics, and enthusiasts to enhance the database with additional insights and intelligence on Common Vulnerabilities and Exposures (CVEs). This move aims to further the understanding and awareness of security advisories by allowing community members to suggest improvements and provide context through a user-friendly interface, with contributions licensed under Creative Commons. The Advisory Database, which supports GitHub's security audit features like Dependabot alerts, follows the Open Source Vulnerabilities (OSV) format to ensure broad accessibility and scalability in vulnerability management. By integrating community input, GitHub hopes to improve the security of software supply chains and foster collaborative efforts in the open-source security landscape.