Queries
securityAdvisories
GitHub Security Advisories.
Typ: SecurityAdvisoryConnection!
Argumente für securityAdvisories
| Name | BESCHREIBUNG |
|---|---|
| Returns the elements in the list that come after the specified cursor. |
| Returns the elements in the list that come before the specified cursor. |
| A list of classifications to filter advisories by. |
| The EPSS percentage to filter advisories by. |
| The EPSS percentile to filter advisories by. |
| Returns the first n elements from the list. |
| Returns the last n elements from the list. |
| Filter advisories to those published since a time in the past. |
| Filter advisories to those updated since a time in the past. |
securityAdvisory
Fetch a Security Advisory by its GHSA ID.
Typ: SecurityAdvisory
Argumente für securityAdvisory
| Name | BESCHREIBUNG |
|---|---|
| GitHub Security Advisory ID. |
securityVulnerabilities
Software Vulnerabilities documented by GitHub Security Advisories.
Typ: SecurityVulnerabilityConnection!
Argumente für securityVulnerabilities
| Name | BESCHREIBUNG |
|---|---|
| Returns the elements in the list that come after the specified cursor. |
| Returns the elements in the list that come before the specified cursor. |
| A list of advisory classifications to filter vulnerabilities by. |
| An ecosystem to filter vulnerabilities by. |
| Returns the first n elements from the list. |
| Returns the last n elements from the list. |
| A package name to filter vulnerabilities by. |
| A list of severities to filter vulnerabilities by. |
Objects
CVSS
The Common Vulnerability Scoring System.
Felder für CVSS
| Name | BESCHREIBUNG |
|---|---|
| The CVSS score associated with this advisory. |
| The CVSS vector string associated with this advisory. |
CvssSeverities
The Common Vulnerability Scoring System.
Felder für CvssSeverities
| Name | BESCHREIBUNG |
|---|---|
| The CVSS v3 severity associated with this advisory. |
| The CVSS v4 severity associated with this advisory. |
CWE
A common weakness enumeration.
CWE Wird implementiert
Felder für CWE
| Name | BESCHREIBUNG |
|---|---|
| The id of the CWE. |
| A detailed description of this CWE. |
| The Node ID of the CWE object. |
| The name of this CWE. |
CWEConnection
The connection type for CWE.
Felder für CWEConnection
| Name | BESCHREIBUNG |
|---|---|
| A list of edges. |
| A list of nodes. |
| Information to aid in pagination. |
| Identifies the total count of items in the connection. |
CWEEdge
An edge in a connection.
Felder für CWEEdge
| Name | BESCHREIBUNG |
|---|---|
| A cursor for use in pagination. |
| The item at the end of the edge. |
EPSS
The Exploit Prediction Scoring System.
Felder für EPSS
| Name | BESCHREIBUNG |
|---|---|
| The EPSS percentage represents the likelihood of a CVE being exploited. |
| The EPSS percentile represents the relative rank of the CVE's likelihood of being exploited compared to other CVEs. |
SecurityAdvisory
A GitHub Security Advisory.
SecurityAdvisory Wird implementiert
Felder für SecurityAdvisory
| Name | BESCHREIBUNG |
|---|---|
| The classification of the advisory. |
| The CVSS associated with this advisory. Warnung
|
| The CVSS associated with this advisory. |
| CWEs associated with this Advisory. |
| Identifies the primary key from the database. |
| This is a long plaintext description of the advisory. |
| The Exploit Prediction Scoring System. |
| The GitHub Security Advisory ID. |
| The Node ID of the SecurityAdvisory object. |
| A list of identifiers for this advisory. |
| The permalink for the advisory's dependabot alerts page. |
| The organization that originated the advisory. |
| The permalink for the advisory. |
| When the advisory was published. |
| A list of references for this advisory. |
| The severity of the advisory. |
| A short plaintext summary of the advisory. |
| When the advisory was last updated. |
| Vulnerabilities associated with this Advisory. Argumente für
|
| When the advisory was withdrawn, if it has been withdrawn. |
SecurityAdvisoryConnection
The connection type for SecurityAdvisory.
Felder für SecurityAdvisoryConnection
| Name | BESCHREIBUNG |
|---|---|
| A list of edges. |
| A list of nodes. |
| Information to aid in pagination. |
| Identifies the total count of items in the connection. |
SecurityAdvisoryEdge
An edge in a connection.
Felder für SecurityAdvisoryEdge
| Name | BESCHREIBUNG |
|---|---|
| A cursor for use in pagination. |
| The item at the end of the edge. |
SecurityAdvisoryIdentifier
A GitHub Security Advisory Identifier.
Felder für SecurityAdvisoryIdentifier
| Name | BESCHREIBUNG |
|---|---|
| The identifier type, e.g. GHSA, CVE. |
| The identifier. |
SecurityAdvisoryPackage
An individual package.
Felder für SecurityAdvisoryPackage
| Name | BESCHREIBUNG |
|---|---|
| The ecosystem the package belongs to, e.g. RUBYGEMS, NPM. |
| The package name. |
SecurityAdvisoryPackageVersion
An individual package version.
Felder für SecurityAdvisoryPackageVersion
| Name | BESCHREIBUNG |
|---|---|
| The package name or version. |
SecurityAdvisoryReference
A GitHub Security Advisory Reference.
Felder für SecurityAdvisoryReference
| Name | BESCHREIBUNG |
|---|---|
| A publicly accessible reference. |
SecurityVulnerability
An individual vulnerability within an Advisory.
Felder für SecurityVulnerability
| Name | BESCHREIBUNG |
|---|---|
| The Advisory associated with this Vulnerability. |
| The first version containing a fix for the vulnerability. |
| A description of the vulnerable package. |
| The severity of the vulnerability within this package. |
| When the vulnerability was last updated. |
| A string that describes the vulnerable package versions. This string follows a basic syntax with a few forms.
|
SecurityVulnerabilityConnection
The connection type for SecurityVulnerability.
Felder für SecurityVulnerabilityConnection
| Name | BESCHREIBUNG |
|---|---|
| A list of edges. |
| A list of nodes. |
| Information to aid in pagination. |
| Identifies the total count of items in the connection. |
SecurityVulnerabilityEdge
An edge in a connection.
Felder für SecurityVulnerabilityEdge
| Name | BESCHREIBUNG |
|---|---|
| A cursor for use in pagination. |
| The item at the end of the edge. |
Enums
SecurityAdvisoryClassification
Classification of the advisory.
Werte für SecurityAdvisoryClassification
| Name | BESCHREIBUNG |
|---|---|
GENERAL | Classification of general advisories. |
MALWARE | Classification of malware advisories. |
SecurityAdvisoryEcosystem
The possible ecosystems of a security vulnerability's package.
Werte für SecurityAdvisoryEcosystem
| Name | BESCHREIBUNG |
|---|---|
ACTIONS | GitHub Actions. |
COMPOSER | PHP packages hosted at packagist.org. |
ERLANG | Erlang/Elixir packages hosted at hex.pm. |
GO | Go modules. |
MAVEN | Java artifacts hosted at the Maven central repository. |
NPM | JavaScript packages hosted at npmjs.com. |
NUGET | .NET packages hosted at the NuGet Gallery. |
PIP | Python packages hosted at PyPI.org. |
PUB | Dart packages hosted at pub.dev. |
RUBYGEMS | Ruby gems hosted at RubyGems.org. |
RUST | Rust crates. |
SWIFT | Swift packages. |
SecurityAdvisorySeverity
Severity of the vulnerability.
Werte für SecurityAdvisorySeverity
| Name | BESCHREIBUNG |
|---|---|
CRITICAL | Critical. |
HIGH | High. |
LOW | Low. |
MODERATE | Moderate. |