
Loading

Loading
We use strictly necessary cookies to run this site, and — only with your consent — analytics cookies to understand how it's used. See our Privacy Policy for details.
Supply chain advisories
50 GitHub-reviewed security advisories archived across the open-source ecosystem — every entry we've published stays live.
This is GitHub's own Security Advisories database — human-reviewed disclosures for vulnerable open-source packages across npm, PyPI, Go, Maven, RubyGems, and more. Unlike our CISA KEV advisories, these aren't all confirmed under active exploitation — they're disclosed vulnerabilities in the dependencies real applications run on. See our piece on third-party and supply chain risk for why this matters even when nothing here is on the news.