Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

The Advisory Database

GitHub's Advisory Database saw a record-breaking number of vulnerability reports in 2024, driven by the CVE program's shift to a new mandated format and increased automation. The database now contains over 240,000 advisories, with significant growth in high-severity vulnerabilities, highlighting the scale and challenges of modern supply-chain security.

Background

GitHub's Advisory Database is a public, curated repository of known security vulnerabilities, similar to a Wikipedia for software flaws. It powers GitHub's "Dependabot" alerts, which tell developers when their projects use insecure code. The record-breaking volume mentioned reflects a broader trend: as security scanning tools get more aggressive and automated vulnerability reporting becomes standard, the sheer number of disclosed flaws has surged, overwhelming maintainers who must triage and fix them. This matters because modern software depends on hundreds of open-source libraries; a single unpatched vulnerability in a dependency can compromise thousands of downstream applications. The piece also touches on the tension between quickly publishing a vulnerability and giving maintainers time to release a fix before attackers exploit it (responsible disclosure vs. full disclosure).

Related stories