---
title: "List repository security advisories"
method: GET
path: "/repos/{owner}/{repo}/security-advisories"
tags: ["security-advisories"]
---

# List repository security advisories

`GET /repos/{owner}/{repo}/security-advisories`

Lists security advisories in a repository.

The authenticated user can access unpublished security advisories from a repository if they are a security manager or administrator of that repository, or if they are a collaborator on any security advisory.

OAuth app tokens and personal access tokens (classic) need the `repo` or `repository_advisories:read` scope to to get a published security advisory in a private repository, or any unpublished security advisory that the authenticated user has access to.

## Path parameters

- `owner` string, required
- `repo` string, required

## Query parameters

- `direction` 'asc' | 'desc'
- `sort` 'created' | 'updated' | 'published'
- `before` string
- `after` string
- `per_page` integer
- `state` 'triage' | 'draft' | 'published' | 'closed'

## Response `200`

Response

- RepositoryAdvisory[]
  - `ghsa_id` string, required — The GitHub Security Advisory ID.
  - `cve_id` string, nullable, required — The Common Vulnerabilities and Exposures (CVE) ID.
  - `url` string, uri, required — The API URL for the advisory.
  - `html_url` string, uri, required — The URL for the advisory.
  - `summary` string, required — A short summary of the advisory.
  - `description` string, nullable, required — A detailed description of what the advisory entails.
  - `severity` 'critical' | 'high' | 'medium' | 'low', nullable, required — The severity of the advisory.
  - `author` SimpleUser, required — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `publisher` SimpleUser, required — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `identifiers` object[], required
    - `type` 'CVE' | 'GHSA', required — The type of identifier.
    - `value` string, required — The identifier value.
  - `state` 'published' | 'closed' | 'withdrawn' | 'draft' | 'triage', required — The state of the advisory.
  - `created_at` string, date-time, nullable, required — The date and time of when the advisory was created, in ISO 8601 format.
  - `updated_at` string, date-time, nullable, required — The date and time of when the advisory was last updated, in ISO 8601 format.
  - `published_at` string, date-time, nullable, required — The date and time of when the advisory was published, in ISO 8601 format.
  - `closed_at` string, date-time, nullable, required — The date and time of when the advisory was closed, in ISO 8601 format.
  - `withdrawn_at` string, date-time, nullable, required — The date and time of when the advisory was withdrawn, in ISO 8601 format.
  - `submission` object, nullable, required
    - `accepted` boolean, required — Whether a private vulnerability report was accepted by the repository's administrators.
  - `vulnerabilities` RepositoryAdvisoryVulnerability[], nullable, required
    - `package` object, nullable, required — The name of the package affected by the vulnerability.
      - `ecosystem` 'rubygems' | 'npm' | 'pip' | 'maven' | 'nuget' | 'composer' | 'go' | 'rust' | 'erlang' | 'actions' | 'pub' | 'other' | 'swift', required — The package's language or package management ecosystem.
      - `name` string, nullable, required — The unique package name within its ecosystem.
    - `vulnerable_version_range` string, nullable, required — The range of the package versions affected by the vulnerability.
    - `patched_versions` string, nullable, required — The package version(s) that resolve the vulnerability.
    - `vulnerable_functions` string[], nullable, required — The functions in the package that are affected.
  - `cvss` object, nullable, required
    - `vector_string` string, nullable, required — The CVSS vector.
    - `score` number, nullable, required — The CVSS score.
  - `cvss_severities` CvssSeverities, nullable
    - `cvss_v3` object, nullable
      - `vector_string` string, nullable, required — The CVSS 3 vector string.
      - `score` number, nullable, required — The CVSS 3 score.
    - `cvss_v4` object, nullable
      - `vector_string` string, nullable, required — The CVSS 4 vector string.
      - `score` number, nullable, required — The CVSS 4 score.
  - `cwes` object[], nullable, required
    - `cwe_id` string, required — The Common Weakness Enumeration (CWE) identifier.
    - `name` string, required — The name of the CWE.
  - `cwe_ids` string[], nullable, required — A list of only the CWE IDs.
  - `credits` object[], nullable, required
    - `login` string — The username of the user credited.
    - `type` 'analyst' | 'finder' | 'reporter' | 'coordinator' | 'remediation_developer' | 'remediation_reviewer' | 'remediation_verifier' | 'tool' | 'sponsor' | 'other' — The type of credit the user is receiving.
  - `credits_detailed` RepositoryAdvisoryCredit[], nullable, required
    - `user` SimpleUser, required — A GitHub user.
      - `name` string, nullable
      - `email` string, nullable
      - `login` string, required
      - `id` integer, required
      - `node_id` string, required
      - `avatar_url` string, uri, required
      - `gravatar_id` string, nullable, required
      - `url` string, uri, required
      - `html_url` string, uri, required
      - `followers_url` string, uri, required
      - `following_url` string, required
      - `gists_url` string, required
      - `starred_url` string, required
      - `subscriptions_url` string, uri, required
      - `organizations_url` string, uri, required
      - `repos_url` string, uri, required
      - `events_url` string, required
      - `received_events_url` string, uri, required
      - `type` string, required
      - `site_admin` boolean, required
      - `starred_at` string
      - `user_view_type` string
    - `type` 'analyst' | 'finder' | 'reporter' | 'coordinator' | 'remediation_developer' | 'remediation_reviewer' | 'remediation_verifier' | 'tool' | 'sponsor' | 'other', required — The type of credit the user is receiving.
    - `state` 'accepted' | 'declined' | 'pending', required — The state of the user's acceptance of the credit.
  - `collaborating_users` SimpleUser[], nullable, required — A list of users that collaborate on the advisory.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `collaborating_teams` Team[], nullable, required — A list of teams that collaborate on the advisory.
    - `id` integer, required
    - `node_id` string, required
    - `name` string, required
    - `slug` string, required
    - `description` string, nullable, required
    - `privacy` string
    - `notification_setting` string
    - `permission` string, required
    - `permissions` object
      - `pull` boolean, required
      - `triage` boolean, required
      - `push` boolean, required
      - `maintain` boolean, required
      - `admin` boolean, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `members_url` string, required
    - `repositories_url` string, uri, required
    - `type` 'enterprise' | 'organization', required — The ownership type of the team
    - `access_source` 'direct' | 'organization' | 'enterprise' — How the team's access to the repository was granted. This property is only present when the team is returned in a repository context, such as `GET /repos/{owner}/{repo}/teams`.
    - `organization_id` integer — Unique identifier of the organization to which this team belongs
    - `enterprise_id` integer — Unique identifier of the enterprise to which this team belongs
    - `parent` NullableTeamSimple, nullable, required — Groups of organization members that gives permissions on specified repositories.
      - `id` integer, required — Unique identifier of the team
      - `node_id` string, required
      - `url` string, uri, required — URL for the team
      - `members_url` string, required
      - `name` string, required — Name of the team
      - `description` string, nullable, required — Description of the team
      - `permission` string, required — Permission that the team will have for its repositories
      - `privacy` string — The level of privacy this team should have
      - `notification_setting` string — The notification setting the team has set
      - `html_url` string, uri, required
      - `repositories_url` string, uri, required
      - `slug` string, required
      - `ldap_dn` string — Distinguished Name (DN) that team maps to within LDAP environment
      - `type` 'enterprise' | 'organization', required — The ownership type of the team
      - `organization_id` integer — Unique identifier of the organization to which this team belongs
      - `enterprise_id` integer — Unique identifier of the enterprise to which this team belongs
  - `private_fork` SimpleRepository, required — A GitHub repository.
    - `id` integer, required — A unique identifier of the repository.
    - `node_id` string, required — The GraphQL identifier of the repository.
    - `name` string, required — The name of the repository.
    - `full_name` string, required — The full, globally unique, name of the repository.
    - `owner` SimpleUser, required — A GitHub user.
      - `name` string, nullable
      - `email` string, nullable
      - `login` string, required
      - `id` integer, required
      - `node_id` string, required
      - `avatar_url` string, uri, required
      - `gravatar_id` string, nullable, required
      - `url` string, uri, required
      - `html_url` string, uri, required
      - `followers_url` string, uri, required
      - `following_url` string, required
      - `gists_url` string, required
      - `starred_url` string, required
      - `subscriptions_url` string, uri, required
      - `organizations_url` string, uri, required
      - `repos_url` string, uri, required
      - `events_url` string, required
      - `received_events_url` string, uri, required
      - `type` string, required
      - `site_admin` boolean, required
      - `starred_at` string
      - `user_view_type` string
    - `private` boolean, required — Whether the repository is private.
    - `html_url` string, uri, required — The URL to view the repository on GitHub.com.
    - `description` string, nullable, required — The repository description.
    - `fork` boolean, required — Whether the repository is a fork.
    - `url` string, uri, required — The URL to get more information about the repository from the GitHub API.
    - `archive_url` string, required — A template for the API URL to download the repository as an archive.
    - `assignees_url` string, required — A template for the API URL to list the available assignees for issues in the repository.
    - `blobs_url` string, required — A template for the API URL to create or retrieve a raw Git blob in the repository.
    - `branches_url` string, required — A template for the API URL to get information about branches in the repository.
    - `collaborators_url` string, required — A template for the API URL to get information about collaborators of the repository.
    - `comments_url` string, required — A template for the API URL to get information about comments on the repository.
    - `commits_url` string, required — A template for the API URL to get information about commits on the repository.
    - `compare_url` string, required — A template for the API URL to compare two commits or refs.
    - `contents_url` string, required — A template for the API URL to get the contents of the repository.
    - `contributors_url` string, uri, required — A template for the API URL to list the contributors to the repository.
    - `deployments_url` string, uri, required — The API URL to list the deployments of the repository.
    - `downloads_url` string, uri, required — The API URL to list the downloads on the repository.
    - `events_url` string, uri, required — The API URL to list the events of the repository.
    - `forks_url` string, uri, required — The API URL to list the forks of the repository.
    - `git_commits_url` string, required — A template for the API URL to get information about Git commits of the repository.
    - `git_refs_url` string, required — A template for the API URL to get information about Git refs of the repository.
    - `git_tags_url` string, required — A template for the API URL to get information about Git tags of the repository.
    - `issue_comment_url` string, required — A template for the API URL to get information about issue comments on the repository.
    - `issue_events_url` string, required — A template for the API URL to get information about issue events on the repository.
    - `issues_url` string, required — A template for the API URL to get information about issues on the repository.
    - `keys_url` string, required — A template for the API URL to get information about deploy keys on the repository.
    - `labels_url` string, required — A template for the API URL to get information about labels of the repository.
    - `languages_url` string, uri, required — The API URL to get information about the languages of the repository.
    - `merges_url` string, uri, required — The API URL to merge branches in the repository.
    - `milestones_url` string, required — A template for the API URL to get information about milestones of the repository.
    - `notifications_url` string, required — A template for the API URL to get information about notifications on the repository.
    - `pulls_url` string, required — A template for the API URL to get information about pull requests on the repository.
    - `releases_url` string, required — A template for the API URL to get information about releases on the repository.
    - `stargazers_url` string, uri, required — The API URL to list the stargazers on the repository.
    - `statuses_url` string, required — A template for the API URL to get information about statuses of a commit.
    - `subscribers_url` string, uri, required — The API URL to list the subscribers on the repository.
    - `subscription_url` string, uri, required — The API URL to subscribe to notifications for this repository.
    - `tags_url` string, uri, required — The API URL to get information about tags on the repository.
    - `teams_url` string, uri, required — The API URL to list the teams on the repository.
    - `trees_url` string, required — A template for the API URL to create or retrieve a raw Git tree of the repository.
    - `hooks_url` string, uri, required — The API URL to list the hooks on the repository.

## Other responses

- `400` — Bad Request
- `404` — Resource not found

---

[API](https://skmtc.net/github/apis/github-v3-rest-api-2.md) · [All operations](https://skmtc.net/github/apis/github-v3-rest-api-2/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/github/github-v3-rest-api-2/versions/8ae6d0c8716e/schema)
