GitHub opens its vulnerabilities Advisory Database to community submissions
GitHub is opening the GitHub Advisory Database to community submissions, some two years after the Microsoft-owned code-hosting platform first launched the vulnerabilities database for public consumption.
The move fits into a broader industrial push to secure the software supply chain, and follows a recent White House-hosted open source security summit which sought to address how best to tackle flaws in community-driven software such as the recently-discovered Log4j vulnerability.