Release

November 14, 20191 Minute Read

GitHub Security Advisories now out of beta and automatic CVE requests

GitHub Security Advisories, which launched in beta earlier this year, are now generally available. And we’ve made some exciting changes based on feedback from maintainers. First, we’ve added the ability to automatically request a CVE identifier for any Security Advisory. We’ve also refined the process of creating and publishing a Security Advisory, so that it’s clearer when the advisory will become public and easier to provide the information needed to power automatic dependency updates via the GitHub Advisory Database.

Learn more about Security Advisories

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

GitHub Security Advisories now out of beta and automatic CVE requests - GitHub Changelog