Security advisory IDs: CVE, GHSA, GO and more
A security advisory ID is the stable name of one published vulnerability, such as a CVE or GHSA id; DevFlow keys each finding on it and plans to rank the top 10 per ecosystem.
Why advisories need ids
The same flaw is discussed in release notes, issue trackers, scanners and dashboards. A stable id lets all of them refer to it without ambiguity, and it lets a tool tell a new finding from one it has already seen.
The common formats
CVE-<year>-<number>: the Common Vulnerabilities and Exposures list, the most widely used scheme;GHSA-xxxx-xxxx-xxxx: GitHub security advisories, used by npm and many other ecosystems;GO-<year>-<number>: the Go vulnerability database;RUSTSEC-<year>-<number>: the RustSec database for Rust crates;PYSEC-<year>-<number>: the Python database.
One flaw often has several aliases, for example a GitHub id and a CVE number for the same bug.
Which id DevFlow keeps
Each scanner reports its own id, and DevFlow stores it in the id field of the finding:
- govulncheck gives the Go id, and DevFlow links it to its page on pkg.go.dev;
- pnpm audit gives the GHSA id, else the first CVE, else a fallback of the form
PNPM-<n>; - pip-audit, cargo-audit and osv-scanner give the id of the advisory they matched;
- the .NET scanner takes the last part of the advisory URL, which for a GitHub advisory is the GHSA id, and falls back to the package name.
Where a scanner gives no link of its own, DevFlow builds one: the GitHub page for a GitHub alias, and an osv.dev page otherwise.
Deduplication
Within one scan, a finding is kept once per package and id. A package reached through two lockfiles or two requirement files is therefore not counted twice, while the same id in two different packages stays as two findings.
On the recurring poll, the id also names the attention item: its title joins the id, the advisory's title and the repository name, so the list can be scanned by id at a glance.
In the planned export
The planned public security pages will rank ids per ecosystem by how often they were reported, counting the latest scan of each repository in the trailing 90 days. The export keeps the top 10, each with its package, severity and link.
A page will only be published for an ecosystem with at least 50 reported vulnerabilities, so a ranking never rests on a handful of scans.
Reading an id
The prefix tells you which database to open first. A GO- id leads to the Go vulnerability database with its call-level detail, a RUSTSEC- id to the crate's entry, and a GitHub or CVE id to the general record that most ecosystems share.
FAQ
Does DevFlow merge a CVE id and a GHSA id that describe the same flaw?
No. DevFlow keeps the id each scanner reports and does not merge aliases, so one flaw can appear under different ids in two ecosystems.
Does DevFlow open a new attention item each time a scan finds the same advisory?
No. DevFlow builds each attention item's external id from the repository and the advisory id, and the poller skips an item whose external id already exists, so a repeated finding stays one item.