POST/repos/{owner}/{repo}/security-advisories

Create a repository security advisory

Creates a new repository security advisory.

In order to create a draft repository security advisory, the authenticated user must be a security manager or administrator of that repository.

OAuth app tokens and personal access tokens (classic) need the repo or repository_advisories:write scope to use this endpoint.

  • RetriesRetries up to 2×, 500ms backoff, 30s timeout.

2 parameters · 9 body fields
ownerstringrequired
The account owner of the repository. The name is not case sensitive.
repostringrequired
The name of the repository without the `.git` extension. The name is not case sensitive.
summarystringrequired
A short summary of the advisory.
descriptionstringrequired
A detailed description of what the advisory impacts.
cve_idstringoptional
The Common Vulnerabilities and Exposures (CVE) ID.
vulnerabilitiesarray<object>required
A product affected by the vulnerability detailed in a repository security advisory.
cwe_idsarray<string>optional
A list of Common Weakness Enumeration (CWE) IDs.
creditsarray<object>optional
A list of users receiving credit for their participation in the security advisory.
severitystringoptional
The severity of the advisory. You must choose between setting this field or `cvss_vector_string`.
Allowed:criticalhighmediumlow
cvss_vector_stringstringoptional
The CVSS vector that calculates the severity of the advisory. You must choose between setting this field or `severity`.
start_private_forkbooleanoptional
Whether to create a temporary private fork of the repository to collaborate on a fix.
Default:false

4 status codes
201Response
ghsa_idstringrequired
The GitHub Security Advisory ID.
cve_idstringrequired
The Common Vulnerabilities and Exposures (CVE) ID.
urlstringrequired
The API URL for the advisory.
html_urlstringrequired
The URL for the advisory.
summarystringrequired
A short summary of the advisory.
descriptionstringrequired
A detailed description of what the advisory entails.
severitystringrequired
The severity of the advisory.
Allowed:criticalhighmediumlow
authorobjectrequired
The author of the advisory.
publisherobjectrequired
The publisher of the advisory.
identifiersarray<object>required
statestringrequired
The state of the advisory.
Allowed:publishedclosedwithdrawndrafttriage
created_atstringrequired
The date and time of when the advisory was created, in ISO 8601 format.
updated_atstringrequired
The date and time of when the advisory was last updated, in ISO 8601 format.
published_atstringrequired
The date and time of when the advisory was published, in ISO 8601 format.
closed_atstringrequired
The date and time of when the advisory was closed, in ISO 8601 format.
withdrawn_atstringrequired
The date and time of when the advisory was withdrawn, in ISO 8601 format.
submissionobjectrequired
vulnerabilitiesarray<object>required
cvssobjectrequired
cvss_severitiesobjectoptional
cwesarray<object>required
cwe_idsarray<string>required
A list of only the CWE IDs.
creditsarray<object>required
credits_detailedarray<object>required
collaborating_usersarray<SimpleUser>required
A list of users that collaborate on the advisory.
collaborating_teamsarray<Team>required
A list of teams that collaborate on the advisory.
private_forkobjectrequired
A temporary private fork of the advisory's repository for collaborating on a fix.
403Forbidden
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
404Resource not found
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
422Validation failed.
messagestringrequired
documentation_urlstringrequired
errorsarray<object>optional

Error handling

A 403 is returned: Forbidden. A 404 is returned: Resource not found. A 422 is returned: Validation failed.

Was this helpful?