GitHub Security Advisories Scraper avatar

GitHub Security Advisories Scraper

Pricing

from $23.63 / 1,000 results

Go to Apify Store
GitHub Security Advisories Scraper

GitHub Security Advisories Scraper

Scrape the GitHub Global Security Advisories database. Filter by type (reviewed/unreviewed/malware), severity, affected package, CVE/GHSA ID, or publish date. Returns CVSS, CWE, affected version ranges, patched versions, references, and credits.

Pricing

from $23.63 / 1,000 results

Rating

0.0

(0)

Developer

ParseForge

ParseForge

Maintained by Community

Actor stats

0

Bookmarked

3

Total users

2

Monthly active users

a day ago

Last modified

Share

ParseForge Banner

πŸ™ GitHub Security Advisories Scraper

πŸš€ Export the GitHub Security Advisories catalogue in seconds. Pull GHSA + CVE-paired advisories with CVSS v4 and v3 scores, affected packages, vulnerable version ranges, first-patched versions, and CWE weakness mappings across 13 ecosystems. No sign-up, no token, no manual pagination.

The GitHub Security Advisories Scraper pulls advisories from the GitHub Security Advisory database and returns 26 normalised fields per record, including the GHSA identifier, paired CVE, summary and full description, CVSS v4 and v3 base scores plus vector strings, every affected package and its vulnerable version range, the first patched version, CWE weakness list, references, credits, and review status. The catalogue is the primary source for npm, pip, RubyGems, Maven, NuGet, Composer, Go, Cargo, Hex, Pub, Swift, GitHub Actions, and other-ecosystem advisories used by Dependabot, GitHub Code Scanning, and the GHSA database itself.

The catalogue covers 25,000+ reviewed and community advisories spanning every major package ecosystem GitHub tracks, plus malware advisories that flag malicious packages discovered in the wild. This Actor makes that data downloadable as CSV, Excel, JSON, or XML in minutes. Filters apply at the source, so you skip pagination, severity normalisation, and patched-version extraction entirely.

🎯 Target AudienceπŸ’‘ Primary Use Cases
Security teams, vulnerability managers, package maintainers, SBOM tool builders, dependency-scanner vendors, incident responders, threat researchersDependabot enrichment, SBOM scanning, package risk reports, malware-package detection, CVE-to-GHSA cross-walks, ecosystem trend analysis

πŸ“‹ What the GitHub Security Advisories Scraper does

Multiple workflows in a single Actor:

  • πŸ†” Single GHSA lookup. Fetch one advisory by its identifier (e.g. GHSA-jfh8-c2jp-5v3q).
  • πŸ“¦ Batch GHSA lookup. Pass an array of GHSA IDs and get every match in one run.
  • πŸ”Ž CVE-paired lookup. Find the GHSA that wraps a given CVE.
  • 🎚️ Severity, type, and ecosystem filters. Restrict to Critical / High / Medium / Low, reviewed / unreviewed / malware, or any of 13 ecosystems.
  • πŸ“¦ Affects filter. Find every advisory that affects a specific package or package@version.
  • 🧬 CWE filter. Slice by weakness numbers (e.g. 79,89,787).
  • πŸ“… Published / updated / modified-after windows. Pull recent advisories or full date-range crawls for incremental syncs.
  • 🚫 Withdrawn-only filter. Surface advisories the GitHub team has marked as withdrawn.

Each record includes the GHSA and CVE IDs, identifiers list, summary and full description, advisory type, severity tier, source code location, references, publication and review timestamps, every affected package with vulnerable range, the first patched version, CVSS v4 and v3 scores, CWEs, and credits.

πŸ’‘ Why it matters: GitHub Security Advisories are the upstream source for Dependabot and most modern dependency scanners. Building your own ingestion means handling pagination, the new cvss_severities shape with v3 + v4, multi-package affect ranges, and the GHSA-to-CVE alias model. This Actor skips all of that and gives you a clean, downloadable dataset.

πŸ“Š Data fields

Each record includes: credits, cve_id, cvssScore, cvssV3Score, cvssV3VectorString, cvssV4Score, cvssV4VectorString, cvssVectorString, cwes, description, firstPatchedVersion, ghsa_id, github_reviewed_at, html_url, identifiers, nvd_published_at, published_at, references, repository_advisory_url, scrapedAt, severity, source_code_location, summary, type, updated_at, url, vulnerabilities. All 27 field names come from a real production run, so what you see here is what lands in your dataset.

⚠️ Good to Know: the GHSA database aliases CVEs, so the same vulnerability can appear under both a GHSA-xxxx-xxxx-xxxx ID and a CVE-xxxx-xxxxx ID. When mapping advisories back to your asset inventory, use the cve_id field to deduplicate against NVD-sourced data.

πŸš€ How to use

  1. πŸ“ Sign up. Create a free account with $5 credit (takes 2 minutes).
  2. 🌐 Open the Actor. Go to the GitHub Security Advisories Scraper page on the Apify Store.
  3. 🎯 Set input. Pick a severity, ecosystem, package, or GHSA ID, then set maxItems.
  4. πŸš€ Run it. Click Start and let the Actor collect your data.
  5. πŸ“₯ Download. Grab your results in the Dataset tab as CSV, Excel, JSON, or XML.

⏱️ Total time from signup to downloaded dataset: 3-5 minutes. No coding required.

πŸ’‘ Pro Tip: browse the complete ParseForge collection for more security and reference-data scrapers.

⚠️ Disclaimer: this Actor is an independent tool and is not affiliated with, endorsed by, or sponsored by GitHub, Microsoft, or any of the package maintainers referenced in the catalogue. All trademarks mentioned are the property of their respective owners. Only publicly available security advisory data is collected.

πŸ†˜ Need Help?

If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our contact form or write to parseforge@protonmail.com. We also take on paid custom data projects.

For faster answers, join our Discord. It's the best place to get support and suggest new actors.