{"id":51570,"date":"2019-12-11T09:00:05","date_gmt":"2019-12-11T17:00:05","guid":{"rendered":"https:\/\/github.blog\/?p=51570"},"modified":"2020-04-15T10:50:59","modified_gmt":"2020-04-15T17:50:59","slug":"behind-the-scenes-github-vulnerability-alerts","status":"publish","type":"post","link":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/","title":{"rendered":"Behind the scenes: GitHub security alerts"},"content":{"rendered":"<p><span style=\"font-weight: 400\">If you have code on GitHub, chances are that you\u2019ve had a security vulnerability alert at some point. Since the feature launched, GitHub has sent more than 62 million security alerts for vulnerable dependencies. <\/span><\/p>\n<h2 id=\"how-does-it-work\"><a class=\"heading-link\" href=\"#how-does-it-work\">How does it work?<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p><span style=\"font-weight: 400\">Vulnerability alerts rely on two pieces of data: an inventory of all the software that your code depends on, and a curated list of known vulnerabilities in open-source code.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Any time you push a change to a dependency manifest file, GitHub has a job that parses those manifest files, and stores your dependency on those packages in the dependency graph. If you\u2019re dependent on something that hasn\u2019t been seen before, a background task runs to get more information about the package from the package registries themselves and adds it. We use the information from the package registries to establish the canonical repository that the package came from, and to help populate metadata like readmes, known versions, and the published licenses.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">On GitHub Enterprise Server, this process works identically, except we don\u2019t get any information from the public package registries in order to protect the privacy of the server and its code.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">The dependency graph supports manifests for JavaScript (npm, Yarn), .NET (Nuget), Java (Maven), PHP (Composer), Python (PyPI), and Ruby (Rubygems). This data powers our vulnerability alerts, but also dependency insights, the used by badge, and the community contributors experiences.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Beyond the dependency graph, we aggregate data from a number of sources and curate those to bring you actionable security alerts. GitHub brings in security vulnerability data from a number of sources, including the <\/span><a href=\"https:\/\/nvd.nist.gov\/\"><span style=\"font-weight: 400\">National Vulnerability Database<\/span><\/a><span style=\"font-weight: 400\"> (a service of the United States National Institute of Standards and Technology), maintainer security advisories from open-source maintainers, community datasources, and our partner <\/span><a href=\"https:\/\/www.whitesourcesoftware.com\/\"><span style=\"font-weight: 400\">WhiteSource<\/span><\/a><span style=\"font-weight: 400\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Once we learn about a vulnerability, it passes through an advanced machine learning model that\u2019s trained to recognize vulnerabilities which impact developers. This model rejects anything that isn\u2019t related to an open-source toolchain. If the model accepts the vulnerability, a bot creates a pull request in a GitHub private repository for our\u00a0 team of curation experts to manually review.<\/span><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" src=\"https:\/\/i0.wp.com\/user-images.githubusercontent.com\/12853539\/68245356-a4cf3e00-ffcb-11e9-8109-a2995424bfc4.png?ssl=1\" \/><\/p>\n<p><span style=\"font-weight: 400\">GitHub curates vulnerabilities because CVEs (Common Vulnerability Entries) are often ambiguous about which open-source projects are impacted. This can be particularly challenging when multiple libraries with similar names exist, or when they\u2019re a part of a larger toolkit. Depending on the kind of vulnerability, our curation team may follow-up with outside security researchers or maintainers about the impact assessment. This follow-up helps to confirm that an alert is warranted and to identify the exact packages that are impacted.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Once the curation team completes the mappings, we merge the pull request and it starts a background job that notifies users about any affected repositories. Depending on the vulnerability, this can cause a lot of alerts. In a recent incident, more than two million repositories were alerted about a vulnerable version of lodash, a popular JavaScript utility library.<\/span><\/p>\n<p><span style=\"font-weight: 400\">GitHub Enterprise Server customers get a slightly different experience. If an admin has enabled security vulnerability alerts through GitHub Connect, the server will download the latest curated list of vulnerabilities from GitHub.com over the private GitHub Connect channel on its next scheduled sync (about once per hour). If a new vulnerability exists, the server determines the impacted users and repositories before generating alerts directly.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Security vulnerabilities are a matter of public good. High-profile breaches impact the trustworthiness of the entire tech industry, so we publish a curated set of vulnerabilities on our <\/span><a href=\"https:\/\/developer.github.com\/v4\/object\/securityadvisory\/\"><span style=\"font-weight: 400\">GraphQL APIs<\/span><\/a><span style=\"font-weight: 400\"> for community projects and enterprise tools to use in custom workflows as necessary. Users can also browse the known vulnerabilities from public sources on the <\/span><a href=\"https:\/\/github.com\/advisories\"><span style=\"font-weight: 400\">GitHub Advisory Database<\/span><\/a><span style=\"font-weight: 400\">.<\/span><\/p>\n<h2 id=\"engineers-behind-the-feature\"><a class=\"heading-link\" href=\"#engineers-behind-the-feature\">Engineers behind the feature<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p><span style=\"font-weight: 400\">Despite advanced technology, security alerting is a human process driven by dedicated GitHubbers. Meet Rob (<\/span><a href=\"https:\/\/github.com\/rschultheis\"><span style=\"font-weight: 400\">@rschultheis<\/span><\/a><span style=\"font-weight: 400\">)<\/span><span style=\"font-weight: 400\">, one of the core members of our security team, and learn about his experiences at GitHub through a friendly Q&amp;A:<\/span><\/p>\n<h6 id=\"humphrey-dogart-german-shepherd-and-rob-schultheis-software-engineer-on-the-github-security-team\"><a class=\"heading-link\" href=\"#humphrey-dogart-german-shepherd-and-rob-schultheis-software-engineer-on-the-github-security-team\"><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" class=\"aligncenter\" src=\"https:\/\/i0.wp.com\/user-images.githubusercontent.com\/12853539\/68245848-8584e080-ffcc-11e9-8626-3180ab509b93.jpg?resize=4032%2C3024&#038;ssl=1\" alt=\"\" width=\"4032\" height=\"3024\" \/><em>Humphrey Dogart (German Shepherd) and Rob Schultheis (Software Engineer on the GitHub Security team)<\/em><span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h6>\n<p><b>How long have you been with GitHub?\u00a0<\/b><\/p>\n<p style=\"padding-left: 40px\"><span style=\"font-weight: 400\">Two years<\/span><\/p>\n<p><b>How did you get into software security?\u00a0<\/b><\/p>\n<p style=\"padding-left: 40px\"><span style=\"font-weight: 400\">I&#8217;ve worked with open source software for most of my 20 year career in tech, and honestly for much of that time I didn\u2019t pay much attention to security. When I started at GitHub I was given the opportunity to work on the first iteration of security alerts. It quickly became clear that having a high quality, open dataset was going to be a critical factor in the success of the feature. I dove into the task of curating that advisory dataset and found a whole side to the industry that was open for exploration, and I&#8217;ve stayed with it ever since!<\/span><\/p>\n<p><b>What are the trickiest parts of vulnerability curation?\u00a0<\/b><\/p>\n<p style=\"padding-left: 40px\"><span style=\"font-weight: 400\">The hardest problem is probably confirming that our advisory data correctly identifies which version(s) of a package are vulnerable to a given advisory, and which version(s) first address it.<\/span><\/p>\n<p><b>What was the most difficult security vulnerability you\u2019ve had to publish?\u00a0<\/b><\/p>\n<p style=\"padding-left: 40px\"><span style=\"font-weight: 400\">One memorable vulnerability was <\/span><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-9284\"><span style=\"font-weight: 400\">CVE-2015-9284<\/span><\/a><span style=\"font-weight: 400\">. This one was tough in several ways because it was a part of a popular library, it was also unpatched when it became fully public, and finally, it was published four years after the initial disclosure to maintainers. Even worse, all attempts to fix it had stalled.<\/span><\/p>\n<p style=\"padding-left: 40px\"><span style=\"font-weight: 400\">We ended up proceeding to publish it and the community quickly responded and finally got the security issue patched.<\/span><\/p>\n<p><b>What\u2019s your favorite feel-good moment working in security?\u00a0<\/b><\/p>\n<p style=\"padding-left: 40px\"><span style=\"font-weight: 400\">Seeing tweets and other feedback thanking us is always wonderful. We do read them! And that goes the same for those critical of the feature or the way certain advisories were disclosed or published. Please keep them coming\u2014they\u2019re really valuable to us as we keep evolving our security offerings.<\/span><\/p>\n<p><b>Since you work at home, can you introduce us to your furry officemate?\u00a0<\/b><\/p>\n<p style=\"padding-left: 40px\"><span style=\"font-weight: 400\">I live with a seven month old shepherd named Humphrey Dogart. His primary responsibilities are making sure I don&#8217;t spend all day on the computer, and he does a great job of that. I think we make a great team!<\/span><\/p>\n<hr \/>\n<p><a href=\"https:\/\/help.github.com\/en\/github\/managing-security-vulnerabilities\/about-security-alerts-for-vulnerable-dependencies\">Learn more about GitHub security alerts<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn more about what\u2019s behind the scenes with GitHub vulnerability alerts.<\/p>\n","protected":false},"author":1646,"featured_media":51611,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gh_post_show_toc":"","_gh_post_is_no_robots":"","_gh_post_is_featured":"","_gh_post_is_excluded":"","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"","_gh_post_sq_img_id":"","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false,"_links_to":"","_links_to_target":""},"categories":[72,3310],"tags":[],"coauthors":[],"class_list":["post-51570","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-engineering","category-platform-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Behind the scenes: GitHub security alerts - The GitHub Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Behind the scenes: GitHub vulnerability alerts\" \/>\n<meta property=\"og:description\" content=\"Learn more about what\u2019s behind the scenes with GitHub vulnerability alerts.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/\" \/>\n<meta property=\"og:site_name\" content=\"The GitHub Blog\" \/>\n<meta property=\"article:published_time\" content=\"2019-12-11T17:00:05+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-04-15T17:50:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2019\/12\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631\" \/>\n\t<meta property=\"og:image:width\" content=\"1201\" \/>\n\t<meta property=\"og:image:height\" content=\"631\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Justin Hutchings\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Behind the scenes: GitHub vulnerability alerts\" \/>\n<meta name=\"twitter:description\" content=\"Learn more about what\u2019s behind the scenes with GitHub vulnerability alerts.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2019\/12\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631\" \/>\n<meta name=\"twitter:creator\" content=\"@jhutchings0\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Justin Hutchings\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/\"},\"author\":{\"name\":\"Justin Hutchings\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/62706a932604181cba95df7791e55719\"},\"headline\":\"Behind the scenes: GitHub security alerts\",\"datePublished\":\"2019-12-11T17:00:05+00:00\",\"dateModified\":\"2020-04-15T17:50:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/\"},\"wordCount\":1038,\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2019\\\/12\\\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631\",\"articleSection\":[\"Engineering\",\"Platform security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/\",\"name\":\"Behind the scenes: GitHub security alerts - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2019\\\/12\\\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631\",\"datePublished\":\"2019-12-11T17:00:05+00:00\",\"dateModified\":\"2020-04-15T17:50:59+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/62706a932604181cba95df7791e55719\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/#primaryimage\",\"url\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2019\\\/12\\\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631\",\"contentUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2019\\\/12\\\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631\",\"width\":1201,\"height\":631},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/behind-the-scenes-github-vulnerability-alerts\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Engineering\",\"item\":\"https:\\\/\\\/github.blog\\\/engineering\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Platform security\",\"item\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Behind the scenes: GitHub security alerts\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/62706a932604181cba95df7791e55719\",\"name\":\"Justin Hutchings\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/555336dfbdc2ef5613459d2c746b02185689d6b8a424d568c3467e9f67e6e4cb?s=96&d=mm&r=g60b305c23ca42f980f658006fa2e47e9\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/555336dfbdc2ef5613459d2c746b02185689d6b8a424d568c3467e9f67e6e4cb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/555336dfbdc2ef5613459d2c746b02185689d6b8a424d568c3467e9f67e6e4cb?s=96&d=mm&r=g\",\"caption\":\"Justin Hutchings\"},\"description\":\"Director of Product Management for supply chain security. I manage the team that's behind Dependabot, the Advisory Database, and the dependency graph. Twitter: https:\\\/\\\/twitter.com\\\/jhutchings0\",\"sameAs\":[\"https:\\\/\\\/x.com\\\/jhutchings0\"],\"url\":\"https:\\\/\\\/github.blog\\\/author\\\/jhutchings1\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Behind the scenes: GitHub security alerts - The GitHub Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/","og_locale":"en_US","og_type":"article","og_title":"Behind the scenes: GitHub vulnerability alerts","og_description":"Learn more about what\u2019s behind the scenes with GitHub vulnerability alerts.","og_url":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/","og_site_name":"The GitHub Blog","article_published_time":"2019-12-11T17:00:05+00:00","article_modified_time":"2020-04-15T17:50:59+00:00","og_image":[{"width":1201,"height":631,"url":"https:\/\/github.blog\/wp-content\/uploads\/2019\/12\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631","type":"image\/png"}],"author":"Justin Hutchings","twitter_card":"summary_large_image","twitter_title":"Behind the scenes: GitHub vulnerability alerts","twitter_description":"Learn more about what\u2019s behind the scenes with GitHub vulnerability alerts.","twitter_image":"https:\/\/github.blog\/wp-content\/uploads\/2019\/12\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631","twitter_creator":"@jhutchings0","twitter_misc":{"Written by":"Justin Hutchings","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/#article","isPartOf":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/"},"author":{"name":"Justin Hutchings","@id":"https:\/\/github.blog\/#\/schema\/person\/62706a932604181cba95df7791e55719"},"headline":"Behind the scenes: GitHub security alerts","datePublished":"2019-12-11T17:00:05+00:00","dateModified":"2020-04-15T17:50:59+00:00","mainEntityOfPage":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/"},"wordCount":1038,"image":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2019\/12\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631","articleSection":["Engineering","Platform security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/","url":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/","name":"Behind the scenes: GitHub security alerts - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/#primaryimage"},"image":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2019\/12\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631","datePublished":"2019-12-11T17:00:05+00:00","dateModified":"2020-04-15T17:50:59+00:00","author":{"@id":"https:\/\/github.blog\/#\/schema\/person\/62706a932604181cba95df7791e55719"},"breadcrumb":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/#primaryimage","url":"https:\/\/github.blog\/wp-content\/uploads\/2019\/12\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631","contentUrl":"https:\/\/github.blog\/wp-content\/uploads\/2019\/12\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631","width":1201,"height":631},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/engineering\/platform-security\/behind-the-scenes-github-vulnerability-alerts\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Engineering","item":"https:\/\/github.blog\/engineering\/"},{"@type":"ListItem","position":3,"name":"Platform security","item":"https:\/\/github.blog\/engineering\/platform-security\/"},{"@type":"ListItem","position":4,"name":"Behind the scenes: GitHub security alerts"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/github.blog\/#\/schema\/person\/62706a932604181cba95df7791e55719","name":"Justin Hutchings","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/555336dfbdc2ef5613459d2c746b02185689d6b8a424d568c3467e9f67e6e4cb?s=96&d=mm&r=g60b305c23ca42f980f658006fa2e47e9","url":"https:\/\/secure.gravatar.com\/avatar\/555336dfbdc2ef5613459d2c746b02185689d6b8a424d568c3467e9f67e6e4cb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/555336dfbdc2ef5613459d2c746b02185689d6b8a424d568c3467e9f67e6e4cb?s=96&d=mm&r=g","caption":"Justin Hutchings"},"description":"Director of Product Management for supply chain security. I manage the team that's behind Dependabot, the Advisory Database, and the dependency graph. Twitter: https:\/\/twitter.com\/jhutchings0","sameAs":["https:\/\/x.com\/jhutchings0"],"url":"https:\/\/github.blog\/author\/jhutchings1\/"}]}},"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pamS32-dpM","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/github.blog\/wp-content\/uploads\/2019\/12\/behind-the-scenes-github-security-alerts.png?fit=1201%2C631","_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/51570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/1646"}],"replies":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/comments?post=51570"}],"version-history":[{"count":8,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/51570\/revisions"}],"predecessor-version":[{"id":51622,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/51570\/revisions\/51622"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media\/51611"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=51570"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/categories?post=51570"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/tags?post=51570"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=51570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}