GitHub Security Advisories, weekly digest (agent-curated)
Weekly digest of newly published GitHub Security Advisories (GHSA) that map to real package ecosystems (pip, npm, go, maven, composer, crates.io, ...). Every advisory published in the trailing 7 complete days with at least one package ``vulnerabilities`` mapping is deduplicated on ghsa_id, normalized across ecosystems (sorted ecosystem:name package set, CVE id, CWE list, affected version ranges, fix availability), and enriched: GitHub severity + CVSS base score -> 0-10 severity_score, GitHub-attached EPSS score/percentile, and a match against a curated ~170-package data/ML universe (ml_stack flag, ml_categories, package_criticality tier 1 foundational .. 3 niche). A documented 0-100 risk_score = 100*(0.50*severity + 0.30*EPSS percentile + 0.20*unpatched) is ranked as risk_rank (ties: CVSS desc, ghsa_id asc) and bucketed into risk_tier p1..p4. Advisories without a package mapping (CVE-imported records with no dependency-triage value) and withdrawn advisories are excluded. Week-granular as-of stamping makes same-window re-runs hash-identical. Columns: snapshot week, fetch timestamp, GHSA id, CVE id, publish and update timestamps, summary, description, severity, CVSS score/vector, EPSS score/percentile, CWEs, packages, ecosystems, ML-stack flag/categories/criticality, fix flag, affected ranges, references, source URL, risk score/tier/rank. Primary key: (snapshot_week, ghsa_id). Cadence: weekly. Nullability: cve_id null when the advisory carries no CVE identifier; cvss_score null when neither cvss.score nor cvss_severities carries a numeric score (severity map used instead); epss_* null when GitHub attaches no EPSS. Caveats: risk_score is a triage heuristic, not a quantified risk measure; version ranges are GitHub-curated and occasionally coarse; the ML universe is curated, not exhaustive. The underlying GitHub Advisory Database is CC-BY-4.0 (commercial_use = yes, attribution required); severity scores, EPSS values and the risk ranking are derived signals computed by this connector. Sample use: filter ml_stack = 1 for the advisories touching your data/ML dependencies, order by risk_rank for what to patch first.
- technology
- cybersecurity
- signals
- advisories
- lignes
- 205 lignes
- Qualité
- 100
- Mis à jour
- 25 sept. 2026
- À jour
- Licence
- Usage commercial OK