Characterizing and Modeling the GitHub Security Advisories Review Pipeline

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Segal, Claudio, Segal, Paulo, Banjar, Carlos Eduardo, Paixão, Felipe de Sant'Anna, Borges, Hudson Silva, Silveira, Paulo, de Almeida, Eduardo Santana, Santos, Joanna C. S., Kocheturov, Anton, Srivastava, Gaurav Kumar, Menasché, Daniel Sadoc
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910182406094848
author Segal, Claudio
Segal, Paulo
Banjar, Carlos Eduardo
Paixão, Felipe de Sant'Anna
Borges, Hudson Silva
Silveira, Paulo
de Almeida, Eduardo Santana
Santos, Joanna C. S.
Kocheturov, Anton
Srivastava, Gaurav Kumar
Menasché, Daniel Sadoc
author_facet Segal, Claudio
Segal, Paulo
Banjar, Carlos Eduardo
Paixão, Felipe de Sant'Anna
Borges, Hudson Silva
Silveira, Paulo
de Almeida, Eduardo Santana
Santos, Joanna C. S.
Kocheturov, Anton
Srivastava, Gaurav Kumar
Menasché, Daniel Sadoc
contents GitHub Security Advisories (GHSA) have become a central component of open-source vulnerability disclosure and are widely used by developers and security tools. A distinctive feature of GHSA is that only a fraction of advisories are reviewed by GitHub, while the mechanisms associated with this review process remain poorly understood. In this paper, we conduct a large-scale empirical study of the GHSA review processes, analyzing over 288,000 advisories spanning 2019-2025. We characterize which advisories are more likely to be reviewed, quantify review delays, and identify two distinct review-latency regimes: a fast path dominated by GitHub Repository Advisories (GRAs) and a slow path dominated by NVD-first advisories. We further develop a queueing model that accounts for this dichotomy based on the structure of the advisory processing pipeline.
format Preprint
id arxiv_https___arxiv_org_abs_2602_06009
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Characterizing and Modeling the GitHub Security Advisories Review Pipeline
Segal, Claudio
Segal, Paulo
Banjar, Carlos Eduardo
Paixão, Felipe de Sant'Anna
Borges, Hudson Silva
Silveira, Paulo
de Almeida, Eduardo Santana
Santos, Joanna C. S.
Kocheturov, Anton
Srivastava, Gaurav Kumar
Menasché, Daniel Sadoc
Cryptography and Security
Software Engineering
GitHub Security Advisories (GHSA) have become a central component of open-source vulnerability disclosure and are widely used by developers and security tools. A distinctive feature of GHSA is that only a fraction of advisories are reviewed by GitHub, while the mechanisms associated with this review process remain poorly understood. In this paper, we conduct a large-scale empirical study of the GHSA review processes, analyzing over 288,000 advisories spanning 2019-2025. We characterize which advisories are more likely to be reviewed, quantify review delays, and identify two distinct review-latency regimes: a fast path dominated by GitHub Repository Advisories (GRAs) and a slow path dominated by NVD-first advisories. We further develop a queueing model that accounts for this dichotomy based on the structure of the advisory processing pipeline.
title Characterizing and Modeling the GitHub Security Advisories Review Pipeline
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2602.06009