Live
Dynamic Tier in Google Cloud Managed Lustre: Cost‑Effective, Low‑Latency Storage for AI and HPCArgo CD 4.0 Visioning and Scaling Lessons from ArgoCon NA 2026Always‑On OpenAI Dots: Free Baseline, Metered Delegation, and What It Means for Cost and GovernanceConfidential Advisory Comments Enable Secure In‑Repo Vulnerability CollaborationHalving Uber Eats Search Latency: Architectural Shifts and Operational TakeawaysStateless GitHub App Tokens – Operational Adjustments for EngineersClaude’s Cowork merge makes Claude an always‑on agent for engineersDoorDash Transitions to an Open‑Weight GenAI Platform: Architecture and Ops ImplicationsDynamic Tier in Google Cloud Managed Lustre: Cost‑Effective, Low‑Latency Storage for AI and HPCArgo CD 4.0 Visioning and Scaling Lessons from ArgoCon NA 2026Always‑On OpenAI Dots: Free Baseline, Metered Delegation, and What It Means for Cost and GovernanceConfidential Advisory Comments Enable Secure In‑Repo Vulnerability CollaborationHalving Uber Eats Search Latency: Architectural Shifts and Operational TakeawaysStateless GitHub App Tokens – Operational Adjustments for EngineersClaude’s Cowork merge makes Claude an always‑on agent for engineersDoorDash Transitions to an Open‑Weight GenAI Platform: Architecture and Ops Implications
GitHub

GitHub GraphQL SecurityAdvisory API gains CVE, timestamps, and server‑side filters

AI SummaryPowered by AI

GitHub added five read‑only fields to the SecurityAdvisory GraphQL object and introduced two new server‑side filters. Engineers can now pull richer advisory data in a single request, reducing REST calls, processing overhead, and rate‑limit consumption.

GitHub has expanded the SecurityAdvisory object in its GraphQL API with five new read‑only fields and introduced two additional server‑side filters on the securityAdvisories query. This change lets AI, cloud, DevOps, and security engineers retrieve richer advisory data without falling back to the REST API, cutting request overhead and simplifying downstream processing.

New fields on SecurityAdvisory

  • cveId: the advisory’s CVE identifier, enabling direct correlation with external vulnerability feeds.
  • sourceCodeLocation: a URL pointing to the affected source code, useful for automated code‑review tooling.
  • githubReviewedAt: timestamp of GitHub’s internal review, providing a reference point for internal triage timelines.
  • nvdPublishedAt: timestamp when the National Vulnerability Database published the record, allowing measurement of lag between public disclosure and GitHub review.
  • repositoryAdvisoryUrl: link to a repository‑specific security advisory when one exists, supporting per‑repo audit workflows.

Server‑side filtering improvements

The securityAdvisories query now accepts severities and isWithdrawn arguments. These filters can be combined with existing ones such as classification, identifier, epss, and date‑range filters. By narrowing results on the server, callers avoid downloading the full advisory set and performing client‑side pruning.

Operational impact

  • Fewer HTTP round trips: a single GraphQL request can replace a REST call plus additional filtering logic.
  • Unified authentication and rate‑limit consumption: one token and one rate‑limit bucket cover the entire advisory fetch.
  • Simpler pipeline design: downstream services can request only the fields they need, reducing payload size and parsing effort.
  • Enables new automation patterns such as severity‑based triage feeds, withdrawn‑advisory audits, and latency tracking from NVD publication to GitHub review.

Related CloudNinjas coverage: DevOps.

What This Means For Practitioners

Update existing GraphQL queries to include the new fields where relevant, and replace any REST‑based advisory lookups with the enriched GraphQL endpoint. Leverage the severities and isWithdrawn filters to offload selection logic to GitHub, conserving rate‑limit headroom and reducing client‑side processing. Consider using githubReviewedAt and nvdPublishedAt timestamps to build internal SLAs around vulnerability response times. Finally, monitor your GraphQL usage to ensure the single‑endpoint approach aligns with your rate‑limit budgeting and authentication strategy.

Originally published atGitHub Changelog