New fields for SecurityAdvisory GraphQL API
GitHub has expanded the SecurityAdvisory object within its GraphQL API by adding five new fields. This update allows developers to retrieve comprehensive data from the GitHub Advisory Database directly through GraphQL queries.
Verified State Diff
Impact & Verification Analysis
Security engineers, DevOps teams, and developers building integrations with the GitHub Advisory Database.
It improves architectural efficiency by enabling unified data fetching, reducing API request overhead, and simplifying the integration of security vulnerability data into CI/CD pipelines.
Full Fact Overview
The update specifically targets the SecurityAdvisory object, which previously lacked parity with the REST API for certain data points. By introducing these five fields—including the cveId—GitHub is streamlining the developer experience by reducing the need for hybrid API implementations. This shift encourages the adoption of GraphQL for security-focused automation and vulnerability management workflows, moving away from the legacy REST endpoints for advisory data retrieval.