---
title: "List repository security advisories for an organization"
method: GET
path: "/orgs/{org}/security-advisories"
tags: ["security-advisories"]
---

# List repository security advisories for an organization

`GET /orgs/{org}/security-advisories`

Lists repository security advisories for an organization.

The authenticated user must be an owner or security manager for the organization to use this endpoint.

OAuth app tokens and personal access tokens (classic) need the `repo` or `repository_advisories:write` scope to use this endpoint.

## Path parameters

- `org` string, required

## Query parameters

- `direction` 'asc' | 'desc'
- `sort` 'created' | 'updated' | 'published'
- `before` string
- `after` string
- `per_page` integer
- `state` 'triage' | 'draft' | 'published' | 'closed'

## Response `200`

Response

- RepositoryAdvisory[]
  - `ghsa_id` string, required — The GitHub Security Advisory ID.
  - `cve_id` string, nullable, required — The Common Vulnerabilities and Exposures (CVE) ID.
  - `url` string, uri, required — The API URL for the advisory.
  - `html_url` string, uri, required — The URL for the advisory.
  - `summary` string, required — A short summary of the advisory.
  - `description` string, nullable, required — A detailed description of what the advisory entails.
  - `severity` 'critical' | 'high' | 'medium' | 'low', nullable, required — The severity of the advisory.
  - `author` SimpleUser, required — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `publisher` SimpleUser, required — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `identifiers` object[], required
    - `type` 'CVE' | 'GHSA', required — The type of identifier.
    - `value` string, required — The identifier value.
  - `state` 'published' | 'closed' | 'withdrawn' | 'draft' | 'triage', required — The state of the advisory.
  - `created_at` string, date-time, nullable, required — The date and time of when the advisory was created, in ISO 8601 format.
  - `updated_at` string, date-time, nullable, required — The date and time of when the advisory was last updated, in ISO 8601 format.
  - `published_at` string, date-time, nullable, required — The date and time of when the advisory was published, in ISO 8601 format.
  - `closed_at` string, date-time, nullable, required — The date and time of when the advisory was closed, in ISO 8601 format.
  - `withdrawn_at` string, date-time, nullable, required — The date and time of when the advisory was withdrawn, in ISO 8601 format.
  - `submission` object, nullable, required
    - `accepted` boolean, required — Whether a private vulnerability report was accepted by the repository's administrators.
  - `vulnerabilities` RepositoryAdvisoryVulnerability[], nullable, required
    - `package` object, nullable, required — The name of the package affected by the vulnerability.
      - `ecosystem` 'rubygems' | 'npm' | 'pip' | 'maven' | 'nuget' | 'composer' | 'go' | 'rust' | 'erlang' | 'actions' | 'pub' | 'other' | 'swift', required — The package's language or package management ecosystem.
      - `name` string, nullable, required — The unique package name within its ecosystem.
    - `vulnerable_version_range` string, nullable, required — The range of the package versions affected by the vulnerability.
    - `patched_versions` string, nullable, required — The package version(s) that resolve the vulnerability.
    - `vulnerable_functions` string[], nullable, required — The functions in the package that are affected.
  - `cvss` object, nullable, required
    - `vector_string` string, nullable, required — The CVSS vector.
    - `score` number, nullable, required — The CVSS score.
  - `cvss_severities` CvssSeverities, nullable
    - `cvss_v3` object, nullable
      - `vector_string` string, nullable, required — The CVSS 3 vector string.
      - `score` number, nullable, required — The CVSS 3 score.
    - `cvss_v4` object, nullable
      - `vector_string` string, nullable, required — The CVSS 4 vector string.
      - `score` number, nullable, required — The CVSS 4 score.
  - `cwes` object[], nullable, required
    - `cwe_id` string, required — The Common Weakness Enumeration (CWE) identifier.
    - `name` string, required — The name of the CWE.
  - `cwe_ids` string[], nullable, required — A list of only the CWE IDs.
  - `credits` object[], nullable, required
    - `login` string — The username of the user credited.
    - `type` 'analyst' | 'finder' | 'reporter' | 'coordinator' | 'remediation_developer' | 'remediation_reviewer' | 'remediation_verifier' | 'tool' | 'sponsor' | 'other' — The type of credit the user is receiving.
  - `credits_detailed` RepositoryAdvisoryCredit[], nullable, required
    - `user` SimpleUser, required — A GitHub user.
      - `name` string, nullable
      - `email` string, nullable
      - `login` string, required
      - `id` integer, required
      - `node_id` string, required
      - `avatar_url` string, uri, required
      - `gravatar_id` string, nullable, required
      - `url` string, uri, required
      - `html_url` string, uri, required
      - `followers_url` string, uri, required
      - `following_url` string, required
      - `gists_url` string, required
      - `starred_url` string, required
      - `subscriptions_url` string, uri, required
      - `organizations_url` string, uri, required
      - `repos_url` string, uri, required
      - `events_url` string, required
      - `received_events_url` string, uri, required
      - `type` string, required
      - `site_admin` boolean, required
      - `starred_at` string
      - `user_view_type` string
    - `type` 'analyst' | 'finder' | 'reporter' | 'coordinator' | 'remediation_developer' | 'remediation_reviewer' | 'remediation_verifier' | 'tool' | 'sponsor' | 'other', required — The type of credit the user is receiving.
    - `state` 'accepted' | 'declined' | 'pending', required — The state of the user's acceptance of the credit.
  - `collaborating_users` SimpleUser[], nullable, required — A list of users that collaborate on the advisory.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `collaborating_teams` Team[], nullable, required — A list of teams that collaborate on the advisory.
    - `id` integer, required
    - `node_id` string, required
    - `name` string, required
    - `slug` string, required
    - `description` string, nullable, required
    - `privacy` string
    - `notification_setting` string
    - `permission` string, required
    - `permissions` object
      - `pull` boolean, required
      - `triage` boolean, required
      - `push` boolean, required
      - `maintain` boolean, required
      - `admin` boolean, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `members_url` string, required
    - `repositories_url` string, uri, required
    - `type` 'enterprise' | 'organization', required — The ownership type of the team
    - `access_source` 'direct' | 'organization' | 'enterprise' — How the team's access to the repository was granted. This property is only present when the team is returned in a repository context, such as `GET /repos/{owner}/{repo}/teams`.
    - `organization_id` integer — Unique identifier of the organization to which this team belongs
    - `enterprise_id` integer — Unique identifier of the enterprise to which this team belongs
    - `parent` NullableTeamSimple, nullable, required — Groups of organization members that gives permissions on specified repositories.
      - `id` integer, required — Unique identifier of the team
      - `node_id` string, required
      - `url` string, uri, required — URL for the team
      - `members_url` string, required
      - `name` string, required — Name of the team
      - `description` string, nullable, required — Description of the team
      - `permission` string, required — Permission that the team will have for its repositories
      - `privacy` string — The level of privacy this team should have
      - `notification_setting` string — The notification setting the team has set
      - `html_url` string, uri, required
      - `repositories_url` string, uri, required
      - `slug` string, required
      - `ldap_dn` string — Distinguished Name (DN) that team maps to within LDAP environment
      - `type` 'enterprise' | 'organization', required — The ownership type of the team
      - `organization_id` integer — Unique identifier of the organization to which this team belongs
      - `enterprise_id` integer — Unique identifier of the enterprise to which this team belongs
  - `private_fork` SimpleRepository, required — A GitHub repository.
    - `id` integer, required — A unique identifier of the repository.
    - `node_id` string, required — The GraphQL identifier of the repository.
    - `name` string, required — The name of the repository.
    - `full_name` string, required — The full, globally unique, name of the repository.
    - `owner` SimpleUser, required — A GitHub user.
      - `name` string, nullable
      - `email` string, nullable
      - `login` string, required
      - `id` integer, required
      - `node_id` string, required
      - `avatar_url` string, uri, required
      - `gravatar_id` string, nullable, required
      - `url` string, uri, required
      - `html_url` string, uri, required
      - `followers_url` string, uri, required
      - `following_url` string, required
      - `gists_url` string, required
      - `starred_url` string, required
      - `subscriptions_url` string, uri, required
      - `organizations_url` string, uri, required
      - `repos_url` string, uri, required
      - `events_url` string, required
      - `received_events_url` string, uri, required
      - `type` string, required
      - `site_admin` boolean, required
      - `starred_at` string
      - `user_view_type` string
    - `private` boolean, required — Whether the repository is private.
    - `html_url` string, uri, required — The URL to view the repository on GitHub.com.
    - `description` string, nullable, required — The repository description.
    - `fork` boolean, required — Whether the repository is a fork.
    - `url` string, uri, required — The URL to get more information about the repository from the GitHub API.
    - `archive_url` string, required — A template for the API URL to download the repository as an archive.
    - `assignees_url` string, required — A template for the API URL to list the available assignees for issues in the repository.
    - `blobs_url` string, required — A template for the API URL to create or retrieve a raw Git blob in the repository.
    - `branches_url` string, required — A template for the API URL to get information about branches in the repository.
    - `collaborators_url` string, required — A template for the API URL to get information about collaborators of the repository.
    - `comments_url` string, required — A template for the API URL to get information about comments on the repository.
    - `commits_url` string, required — A template for the API URL to get information about commits on the repository.
    - `compare_url` string, required — A template for the API URL to compare two commits or refs.
    - `contents_url` string, required — A template for the API URL to get the contents of the repository.
    - `contributors_url` string, uri, required — A template for the API URL to list the contributors to the repository.
    - `deployments_url` string, uri, required — The API URL to list the deployments of the repository.
    - `downloads_url` string, uri, required — The API URL to list the downloads on the repository.
    - `events_url` string, uri, required — The API URL to list the events of the repository.
    - `forks_url` string, uri, required — The API URL to list the forks of the repository.
    - `git_commits_url` string, required — A template for the API URL to get information about Git commits of the repository.
    - `git_refs_url` string, required — A template for the API URL to get information about Git refs of the repository.
    - `git_tags_url` string, required — A template for the API URL to get information about Git tags of the repository.
    - `issue_comment_url` string, required — A template for the API URL to get information about issue comments on the repository.
    - `issue_events_url` string, required — A template for the API URL to get information about issue events on the repository.
    - `issues_url` string, required — A template for the API URL to get information about issues on the repository.
    - `keys_url` string, required — A template for the API URL to get information about deploy keys on the repository.
    - `labels_url` string, required — A template for the API URL to get information about labels of the repository.
    - `languages_url` string, uri, required — The API URL to get information about the languages of the repository.
    - `merges_url` string, uri, required — The API URL to merge branches in the repository.
    - `milestones_url` string, required — A template for the API URL to get information about milestones of the repository.
    - `notifications_url` string, required — A template for the API URL to get information about notifications on the repository.
    - `pulls_url` string, required — A template for the API URL to get information about pull requests on the repository.
    - `releases_url` string, required — A template for the API URL to get information about releases on the repository.
    - `stargazers_url` string, uri, required — The API URL to list the stargazers on the repository.
    - `statuses_url` string, required — A template for the API URL to get information about statuses of a commit.
    - `subscribers_url` string, uri, required — The API URL to list the subscribers on the repository.
    - `subscription_url` string, uri, required — The API URL to subscribe to notifications for this repository.
    - `tags_url` string, uri, required — The API URL to get information about tags on the repository.
    - `teams_url` string, uri, required — The API URL to list the teams on the repository.
    - `trees_url` string, required — A template for the API URL to create or retrieve a raw Git tree of the repository.
    - `hooks_url` string, uri, required — The API URL to list the hooks on the repository.

## Other responses

- `400` — Bad Request
- `404` — Resource not found

---

[API](https://skmtc.net/github/apis/rest-api.md) · [All operations](https://skmtc.net/github/apis/rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/github/rest-api/versions/80850db290cd/schema)
