Skip to content

Advisories change after the upgrade.

as of the 2026-09-07 snapshot

About 1 in 9

GitHub-reviewed advisories were edited after publication: 4,148 of 35,259 compared (11.8%). In 131 the fix version changed.

Advisories, counted once each, never added to CVE-record figures; 5,026 rows behind them. Every count is a floor: 13,779 of 35,259 reached our copy over 7 days after publication, and an edit in between is invisible.

By ecosystem

1,846 rows name a package
Advisories that changed, by ecosystemadvisories, not rows or packages

One unit, held across the whole chart. The table carries rows and packages as well.

npm, PyPI and Maven first, then by count. Drawn by advisory because one advisory can name many packages: NuGet's rows outnumber its advisories three to one.

Every ecosystem named by an advisory row, largest first. Each line gives the rows, the advisories behind them and the packages they name, then the two kinds of change those rows split into. Rows, advisories and packages are three different numbers and none is derived from another.
EcosystemRows, Change rows naming a package in this ecosystem.Advisories, Distinct advisories those rows come from. Smaller than the row count wherever one advisory added several packages.Packages, Distinct packages named. Smaller than the row count wherever one package was named by several advisories.Fix version changed, Rows where the version this package was already said to be fixed in later changed.Package added later, Rows where the package was not named as affected when the advisory was published and is named now, with a bar scaled to the largest ecosystem in this table.
Maven71848345836682
Packagist2782259125253
NuGet247731744243
PyPI2111658426185
Go17313911516157
npm9479792668
RubyGems746326866
crates.io2926221019
Swift202011020
GitHub Actions11101
Hex11101

No column here is a rate. The 35,259 advisories compared covers all 11 ecosystems together, and the file carries no count of advisories compared per ecosystem, so this table can say how many npm advisories were edited and cannot say what share of npm advisories that is. The chart ranks by advisories and the table by rows, so their orders differ. Rows, advisories and packages are three different numbers: one advisory that named eleven further packages is one advisory and eleven rows.

3,180 further rows name no ecosystem and are not in this table: a severity level and a withdrawal belong to the whole advisory, the database records neither against a package, and none of them is guessed into one. They are in the table below.

Advisory change types

every counted row is here
The four kinds of edit, most consequential first. Each row gives the comparison, the advisories and the rows carrying it, the version changes its false-positive filter refused, and the median lag where the kind has one.
Kind of editWhat is comparedAdvisories, Advisories carrying this kind of change. Advisories, never CVE records: the two are different catalogs and are never added together.Rows, Change rows: one per change, and for the two package-grained kinds one per package inside it.Refused as bad data, Version changes this kind's own false-positive filter refused as bad data. Counted by reason and never kept as rows, so they cannot be read one by one.Median days to revision, Median days from publication to the initial value’s first observed replacement, measured from the advisory's own publication date. Where it says not dated, the kind carries no date for the change at all.
Advisory fix version movedThe advisory states a higher fixed version for the same package and release branch.1311511,96413.0 d
Package added to advisoryThe advisory added an affected package.1,0591,695327161.1 d
Advisory severity changedwhole advisory, no packageThe advisory changed its published severity label. The evidence identifies whether its scoring vector also changed.2,8002,800012.6 d
Advisory withdrawnwhole advisory, no packageThe advisory now carries a withdrawal timestamp.380380081.8 d

The moved-fix-version finding here is small, and the small number is the finding. 151 rows across 131 advisories, set against 365 rows across 228 records in the CVE catalog: two catalogs and two units, compared rows to rows and advisories to records, never as one total. Most of the gap is format and concentration, not care: advisories state a first-fixed version, the CVE side also counts a last-affected version being raised as its own kind, and the CVE side is dominated by a few publishers’ bulk regenerations, which have no analogue here. The volume in this source is severity changes and added packages, and 3,180 of its 5,026 rows belong to the whole advisory rather than to any one package.

Every change counted from this source is on this site, so an advisory with no row here had no change of that kind. Refused rows on the CVE side are sampled at 250 per class; counted rows are complete. No finding here is not an all clear. It means this check found nothing in the history it can see, not that nothing happened.

Browse every advisory change →·Changes to CVE records and CISA KEV entries →

Data sources and quality

GitHub Advisory Database, github/advisory-database at f6d4e024d0b3. ghsa.json engine 2026.09.05 schema 3

An advisory is an entry in the GitHub Advisory Database, the GHSA page a Dependabot alert links to. It is not a CVE record. Advisories are counted in advisories and the CVE catalog is counted in records, so the two totals describe different catalogs and are never added together.

The advisories are read from a public repository of files, where a commit is one dated save, so the first mirrored commit is the earliest copy of an advisory we can read. Backfilled means a file was added to that repository in a batch, later than the day the advisory itself went out. A release branch is one line of versions kept going in parallel, 4.1.x beside 4.2.x, each with its own fix, and introduced is the field in an advisory naming the first affected version of a branch, which is what tells one branch from another.

Not checked:Advisories GitHub reviewed itself, and no others. The unreviewed part of the database is imported from elsewhere, so a change there is churn upstream rather than GitHub revising its own claim, and it is never compared. This source has no 2023 floor and its history runs back to 2017, which is not the same as having no blind spot. It has one, and it is late arrival: a large share of reviewed advisories reached that repository more than a week after GitHub published them, most in a single commit on 2022-02-15; the figures are printed beside the tables they bound, from the published file. For those, the version read here as the state at publication is the state on the day the advisory arrived, so every change made in between is invisible. An advisory GitHub never reviewed produces no row at all. Both are gaps in what was looked at, not findings that nothing changed.

Not compared:13,779 of 35,259 github-reviewed advisories (39.1%) have their first mirrored commit more than 7 days after their own `published` date, 6,102 of them in the single backfill commit a251e548917. For those, what we read as the state at publication is the state at that backfill commit, so every change made between publication and that commit is invisible here. This source has no 2023 floor, but it does have a backfill horizon, and the two are not the same guarantee. This and the block above describe the same gap from two ends: one names the batch by the day it was committed, the other by that commit's own id.

Not compared:17 further advisories could not be read at one end of the comparison. They are excluded, not assumed unchanged.

A fixed-in version is compared within one release branch, keyed by the range's introduced value. Taking the highest version across a whole package instead would report a newly added branch as though an existing branch's fix had changed.

2,291 more version changes looked like a fix version moving and were refused as bad data, so they are in no figure on this page: 1,676 range restructured, 269 fix version retreated, 12 publication batch correction, 3 version scheme changed, 2 product line renumbered, 1 pseudoversion normalized, 1 unorderable pair, 289 already named at publication, 27 ecosystem relabelled, 11 name normalised. Version numbers are not all written the same way — some count up, 1.2.3 then 1.2.4, some are dates, 2024.11 — and comparing one kind against the other gets the direction wrong, so those pairs are thrown out rather than reported. They are counted by reason rather than kept as rows, so they cannot be read here one by one; each rule is stated in full, with what was done about it, in the method.

A withdrawal uses the timestamp the advisory states. Other kinds use history replay: firstReplacedAt ends the original value's observed interval, while observedAt dates the first appearance of the reported current value. These can differ. An unreadable history state prevents claiming an uninterrupted interval. Publication dates before the mirror's first observation remain a backfill limitation. Adjacent transitions instead measure from the prior value's first observed appearance and never enter endpoint totals.

There is no 2023 cut-off on this source, because the advisory database carries its full history, and there is no database behind it: these findings are served from the shipped analysis on every deployment.

Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. Not affiliated with or endorsed by GitHub.

Shipped snapshot computed 2026-09-07 from catalog commit 1f78fd2580c1. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.