Skip to content

New open-source package security advisories (weekly)

Commercial use OKFreshLicense: CC-BY-4.0
Query in workbench

Follow this dataset

Get a notice in your feed when a new snapshot is published. Optionally, we also POST it to your webhook.

Must be a public https address. We never follow redirects.

Sample onlyDownload sample CSVDownload sample JSONSample rows only (up to 20) — not the complete dataset.

Weekly digest of newly published GitHub Security Advisories (GHSA) that map to real package ecosystems (pip, npm, go, maven, composer, crates.io, ...). Every advisory published in the trailing 7 complete days with at least one package ``vulnerabilities`` mapping is deduplicated on ghsa_id, normalized across ecosystems (sorted ecosystem:name package set, CVE id, CWE list, affected version ranges, fix availability), and enriched: GitHub severity + CVSS base score -> 0-10 severity_score, GitHub-attached EPSS score/percentile, and a match against a curated ~170-package data/ML universe (ml_stack flag, ml_categories, package_criticality tier 1 foundational .. 3 niche). A documented 0-100 risk_score = 100*(0.50*severity + 0.30*EPSS percentile + 0.20*unpatched) is ranked as risk_rank (ties: CVSS desc, ghsa_id asc) and bucketed into risk_tier p1..p4. Advisories without a package mapping (CVE-imported records with no dependency-triage value) and withdrawn advisories are excluded. Week-granular as-of stamping makes same-window re-runs hash-identical. Columns: snapshot week, fetch timestamp, GHSA id, CVE id, publish and update timestamps, summary, description, severity, CVSS score/vector, EPSS score/percentile, CWEs, packages, ecosystems, ML-stack flag/categories/criticality, fix flag, affected ranges, references, source URL, risk score/tier/rank. Primary key: (snapshot_week, ghsa_id). Cadence: weekly. Nullability: cve_id null when the advisory carries no CVE identifier; cvss_score null when neither cvss.score nor cvss_severities carries a numeric score (severity map used instead); epss_* null when GitHub attaches no EPSS. Caveats: risk_score is a triage heuristic, not a quantified risk measure; version ranges are GitHub-curated and occasionally coarse; the ML universe is curated, not exhaustive. The underlying GitHub Advisory Database is CC-BY-4.0 (commercial_use = yes, attribution required); severity scores, EPSS values and the risk ranking are derived signals computed by this connector. Sample use: filter ml_stack = 1 for the advisories touching your data/ML dependencies, order by risk_rank for what to patch first.

Rows
205
Columns
26
Source cadence
Weekly
Last refreshed
Sep 25, 2026
Theme
technology

Use your own AI key

Once today's free allowance is used up, AI features can run on your own provider account.

Kept in this browser tab only (cleared when you close it) and sent with each AI request. Our servers use it for that request and never store or log it.