Patch intelligence record
GitHub / Copilot New fields for SecurityAdvisory GraphQL API
Too few reports for a verdict yet.
- Accepted reports
- 0
- Latest evidence run
- Healthy sources
- 0 fresh (success / no reports) · need 2
Monitoring reflects community-evidence collection health for this exact release — an absence of reports is not a safety guarantee, and this is separate from the AUXSAYS verdict.
Vendor Known Issues — No vendor-known issue data captured for this patch.
AUXSAYS has not captured official issue data for this patch. This does not indicate the vendor has no issues. Not counted as community reports.
Official Patch Notes — vendor release notes captured from the official source
You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API. The SecurityAdvisory object gained five new fields: cveId : The advisory’s CVE identifier. sourceCodeLocation : A link to the affected source code relevant to the advisory. githubReviewedAt : When GitHub reviewed the advisory. nvdPublishedAt : When the National Vulnerability Database (NVD) published its record. repositoryAdvisoryUrl : A link to the linked repository security advisory when there is one. The securityAdvisories query also gained two new filters, severities and isWithdrawn , so you can narrow results on the server instead of downloading everything and filtering it yourself. They work alongside the filters you already use, such as classification, identifier, EPSS, and published or updated since. This means fewer round trips, one authentication path, and one rate limit budget for integrations that read advisory data. It also makes it easier to build things like severity-based triage feeds, withdrawn advisory audits, and tracking of how quickly advisories move from NVD publication to GitHub review. These changes are additive and read-only, so your existing queries keep working. Learn more in the GraphQL API documentation and share your feedback . The post New fields for SecurityAdvisory GraphQL API appeared first on The GitHub Blog .
GitHub / Copilot in these notes: .
You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API.
The SecurityAdvisory object gained five new fields:
cveId : The advisory’s CVE identifier. sourceCodeLocation : A link to the affected source code relevant to the advisory. githubReviewedAt : When GitHub reviewed the advisory. nvdPublishedAt : When the National Vulnerability Database (NVD) published its record. repositoryAdvisoryUrl : A link to the linked repository security advisory when there is one.
The securityAdvisories query also gained two new filters, severities and isWithdrawn , so you can narrow results on the server instead of downloading everything and filtering it yourself. They work alongside the filters you already use, such as classification, identifier, EPSS, and published or updated since.
This means fewer round trips, one authentication path, and one rate limit budget for integrations that read advisory data. It also makes it easier to build things like severity-based triage feeds, withdrawn advisory audits, and tracking of how quickly advisories move from NVD publication to GitHub review.
These changes are additive and read-only, so your existing queries keep working.
Learn more in the GraphQL API documentation and share your feedback .
The post New fields for SecurityAdvisory GraphQL API appeared first on The GitHub Blog .
Technical Details
- Released
- Oct 2, 2026
- File size
- Official source checked
- Oct 3, 2026
- Official notes checked
- Oct 3, 2026
Checksum
Use these hashes to verify downloaded installers match the files published with the official release.
User Reports / Sources (0)
No user report sources have been counted for this record yet.
Official sources
- GitHub. (2026, October 2). GitHub / Copilot New fields for SecurityAdvisory GraphQL API.rss-feed
- GitHub. Download page.download