GET/repos/{owner}/{repo}/security-advisories

List repository security advisories

Lists security advisories in a repository.

The authenticated user can access unpublished security advisories from a repository if they are a security manager or administrator of that repository, or if they are a collaborator on any security advisory.

OAuth app tokens and personal access tokens (classic) need the repo or repository_advisories:read scope to to get a published security advisory in a private repository, or any unpublished security advisory that the authenticated user has access to.

  • RetriesRetries up to 2×, 500ms backoff, 30s timeout.

8 parameters
ownerstringrequired
The account owner of the repository. The name is not case sensitive.
repostringrequired
The name of the repository without the `.git` extension. The name is not case sensitive.
directionstringoptional
The direction to sort the results by.
Allowed:ascdescDefault:desc
sortstringoptional
The property to sort the results by.
Allowed:createdupdatedpublishedDefault:created
beforestringoptional
A cursor, as given in the [Link header](https://docs.github.com/rest/guides/using-pagination-in-the-rest-api#using-link-headers). If specified, the query only searches for results before this cursor. For more information, see "[Using pagination in the REST API](https://docs.github.com/rest/using-the-rest-api/using-pagination-in-the-rest-api)."
afterstringoptional
A cursor, as given in the [Link header](https://docs.github.com/rest/guides/using-pagination-in-the-rest-api#using-link-headers). If specified, the query only searches for results after this cursor. For more information, see "[Using pagination in the REST API](https://docs.github.com/rest/using-the-rest-api/using-pagination-in-the-rest-api)."
per_pageintegeroptional
The number of advisories to return per page. For more information, see "[Using pagination in the REST API](https://docs.github.com/rest/using-the-rest-api/using-pagination-in-the-rest-api)."
Default:30
statestringoptional
Filter by state of the repository advisories. Only advisories of this state will be returned.
Allowed:triagedraftpublishedclosed

3 status codes
200Response
ghsa_idstringrequired
The GitHub Security Advisory ID.
cve_idstringrequired
The Common Vulnerabilities and Exposures (CVE) ID.
urlstringrequired
The API URL for the advisory.
html_urlstringrequired
The URL for the advisory.
summarystringrequired
A short summary of the advisory.
descriptionstringrequired
A detailed description of what the advisory entails.
severitystringrequired
The severity of the advisory.
Allowed:criticalhighmediumlow
authorobjectrequired
The author of the advisory.
publisherobjectrequired
The publisher of the advisory.
identifiersarray<object>required
statestringrequired
The state of the advisory.
Allowed:publishedclosedwithdrawndrafttriage
created_atstringrequired
The date and time of when the advisory was created, in ISO 8601 format.
updated_atstringrequired
The date and time of when the advisory was last updated, in ISO 8601 format.
published_atstringrequired
The date and time of when the advisory was published, in ISO 8601 format.
closed_atstringrequired
The date and time of when the advisory was closed, in ISO 8601 format.
withdrawn_atstringrequired
The date and time of when the advisory was withdrawn, in ISO 8601 format.
submissionobjectrequired
vulnerabilitiesarray<object>required
cvssobjectrequired
cvss_severitiesobjectoptional
cwesarray<object>required
cwe_idsarray<string>required
A list of only the CWE IDs.
creditsarray<object>required
credits_detailedarray<object>required
collaborating_usersarray<SimpleUser>required
A list of users that collaborate on the advisory.
collaborating_teamsarray<Team>required
A list of teams that collaborate on the advisory.
private_forkobjectrequired
A temporary private fork of the advisory's repository for collaborating on a fix.
400Bad Request
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
404Resource not found
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional

Error handling

A 400 is returned: Bad Request. A 404 is returned: Resource not found.

Was this helpful?