Up until today, the GitHub Advisory Database has only published advisories that have been curated and approved by our Security Lab team.
This approach meant users sometimes couldn't find advisories in our database when searching, so the Advisory Database now has a separate section of listings for unreviewed advisories. These will be auto-published from the National Vulnerability Database feed.
If you search for a term like "WordPress plugin," you can now see listings that are both GitHub reviewed and unreviewed. If you'd like to filter for only reviewed advisories, add type:reviewed
to your query. Alternatively, you can also enter your query and then click the "All reviewed" button on the left-hand sidebar.
Dependabot alerts will continue to only be generated for GitHub Reviewed advisories in order to preserve their curated level of quality.