Characterizing and Modeling the GitHub Security Advisories Review Pipeline
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866910182406094848 |
|---|---|
| author | Segal, Claudio Segal, Paulo Banjar, Carlos Eduardo Paixão, Felipe de Sant'Anna Borges, Hudson Silva Silveira, Paulo de Almeida, Eduardo Santana Santos, Joanna C. S. Kocheturov, Anton Srivastava, Gaurav Kumar Menasché, Daniel Sadoc |
| author_facet | Segal, Claudio Segal, Paulo Banjar, Carlos Eduardo Paixão, Felipe de Sant'Anna Borges, Hudson Silva Silveira, Paulo de Almeida, Eduardo Santana Santos, Joanna C. S. Kocheturov, Anton Srivastava, Gaurav Kumar Menasché, Daniel Sadoc |
| contents | GitHub Security Advisories (GHSA) have become a central component of open-source vulnerability disclosure and are widely used by developers and security tools. A distinctive feature of GHSA is that only a fraction of advisories are reviewed by GitHub, while the mechanisms associated with this review process remain poorly understood. In this paper, we conduct a large-scale empirical study of the GHSA review processes, analyzing over 288,000 advisories spanning 2019-2025. We characterize which advisories are more likely to be reviewed, quantify review delays, and identify two distinct review-latency regimes: a fast path dominated by GitHub Repository Advisories (GRAs) and a slow path dominated by NVD-first advisories. We further develop a queueing model that accounts for this dichotomy based on the structure of the advisory processing pipeline. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2602_06009 |
| institution | arXiv |
| publishDate | 2026 |
| record_format | arxiv |
| spellingShingle | Characterizing and Modeling the GitHub Security Advisories Review Pipeline Segal, Claudio Segal, Paulo Banjar, Carlos Eduardo Paixão, Felipe de Sant'Anna Borges, Hudson Silva Silveira, Paulo de Almeida, Eduardo Santana Santos, Joanna C. S. Kocheturov, Anton Srivastava, Gaurav Kumar Menasché, Daniel Sadoc Cryptography and Security Software Engineering GitHub Security Advisories (GHSA) have become a central component of open-source vulnerability disclosure and are widely used by developers and security tools. A distinctive feature of GHSA is that only a fraction of advisories are reviewed by GitHub, while the mechanisms associated with this review process remain poorly understood. In this paper, we conduct a large-scale empirical study of the GHSA review processes, analyzing over 288,000 advisories spanning 2019-2025. We characterize which advisories are more likely to be reviewed, quantify review delays, and identify two distinct review-latency regimes: a fast path dominated by GitHub Repository Advisories (GRAs) and a slow path dominated by NVD-first advisories. We further develop a queueing model that accounts for this dichotomy based on the structure of the advisory processing pipeline. |
| title | Characterizing and Modeling the GitHub Security Advisories Review Pipeline |
| topic | Cryptography and Security Software Engineering |
| url | https://arxiv.org/abs/2602.06009 |