GHSA

GitHub Security Advisory

GitHub-Sicherheitshinweis

A GHSA is an entry in the GitHub Advisory Database, which primarily captures vulnerabilities in open-source dependencies across various programming-language ecosystems. It carries its own identifier in the format GHSA-xxxx-xxxx-xxxx and can exist before or without a classic CVE-ID. For the software supply chain, GHSA is therefore one of the fastest sources.

History & facts. As software shifted towards open package ecosystems, a need arose for vulnerability data tied directly to package versions rather than product names. GitHub is also a CNA and can issue CVE-IDs; the GHSA database links both worlds and feeds tools such as automated dependency checking. The data is openly licensed and machine-readable. Outlook & recommendation. For development organisations, GHSA is often the most timely warning because it is published without the detour of a formal CVE assignment. Combined with a software bill of materials (SBOM), this makes it possible to determine precisely which application contains which vulnerable component — a core requirement that becomes mandatory for manufacturers under the CRA.
GHSA — GitHub Security Advisory