About this dataset
Tracks newly published and updated GitHub Security Advisories (GHSA) — the ecosystem-specific vulnerability feed dependency-audit agents actually need: per-package vulnerable version ranges and first_patched_version for npm, pip, Go, Composer, Cargo, Maven, NuGet and more, plus GitHub's malicious-package (malware) advisories that NVD's CVE feed does not carry. Rows carry severity (low/moderate/critical), CVSS score where available, affected ecosystems and packages, vulnerable ranges and patched versions — everything a patch-triage or dependency-audit agent needs to decide 'am I affected, what do I upgrade to'. Distinct from NVD CVE feeds (cvewatch) and CISA KEV (kevwatch): GHSA is package-ecosystem-specific with patched-version data. Source is the public GitHub Advisories API (keyless); corpus refreshed and republished hourly, anchored on-chain every run for verifiable freshness.