GitHub Adds Five New Fields and Filters to SecurityAdvisory
Developers can now access more of the GitHub Advisory Database directly through the GraphQL API without needing to fall back to the REST API, following a recent update that introduces new fields and server-side filters.

Expanded GraphQL API Capabilities
According to the official GitHub Changelog, developers can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API. This update expands the capabilities of the SecurityAdvisory object by introducing critical data points directly into the GraphQL schema, simplifying integration workflows for developer tools and security platforms. Further details are available from GitHub Changelog in the original source material.
The SecurityAdvisory object gained five new fields to help developers retrieve more precise data. These additions consist of sourceCodeLocation, which links to the affected source code relevant to the advisory; githubReviewedAt, indicating when GitHub reviewed the advisory; nvdPublishedAt, showing when the National Vulnerability Database published its record; repositoryAdvisoryUrl, providing a link to the linked repository security advisory when applicable; and cveId.
New Server-Side Filtering Options
In addition to the new fields, the securityAdvisories query has been updated with two new filters: severities and isWithdrawn. These new filters allow developers to narrow search results directly on the server rather than downloading entire datasets and filtering them locally on the client side.
These additions operate alongside existing filtering options that developers already utilize, such as classification, identifier, EPSS, and published or updated since filters. By moving filtering operations to the server side, integrations can operate more efficiently and process data with greater speed.
Efficiency and Workflow Improvements
The introduction of these fields and filters translates to fewer network round trips, a single authentication path, and a unified rate limit budget for software integrations that routinely read vulnerability and advisory data. This architectural optimization makes it significantly easier to construct specialized applications.
Specifically, developers can more seamlessly build features such as severity-based triage feeds, withdrawn advisory audits, and tracking systems that monitor how quickly security advisories transition from initial National Vulnerability Database publication to comprehensive GitHub review.
Backward Compatibility and Implementation
GitHub has designed these updates to be entirely additive and read-only. Consequently, developers and maintainers can rest assured that their existing queries will keep working without requiring immediate code rewrites or emergency maintenance cycles.
Teams looking to incorporate the new fields into their current workflows can consult the official documentation for further guidance, and developers are encouraged to share their feedback with the platform community as they test out the enhanced query options.
Sources
- GitHub ChangelogNew fields for SecurityAdvisory GraphQL API
Continue chronologically





