Ingesting of Drupal advisory database
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
Review the Drupal advisory database and the OSV ingestion context linked in the issue, then trace how GitHub currently consumes OSV advisories. Determine whether production ingestion is sufficient for GitHub tools such as Dependabot; done means documenting the required next step or confirming that no further integration work is needed.
Written by the indexing model from the issue text.
Description
We've been working with the Drupal community and OSV team to have Drupal advisories published in OSV format and ingested into osv.dev, with the database living here: https://github.com/DrupalSecurityTeam/drupal-advisory-database
We've recently gotten the database ingested into the test instance of osv.dev, and plan to have it moved to production ideally at the start of December. The database has been ingested into osv.dev since December 2025
I wanted to check if there is anything else needed to have GitHub use these advisories for tools like dependabot, or if having the advisories ingested into osv.dev is enough.
Note that while the database is not currently in production, we believe the advisories are stable and suitable to be used in production (the database is now in production)
- Dominant language
- No language data
- Stars
- 2.5k
- Forks
- 772
- Avg merge
- 3d 15h
- Merged PRs (30d)
- 46
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/advisory-database
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#9255 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#9164 · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8994 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#8898 · 4 comments · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8841 ·
All issues in github/advisory-database
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Business User Story
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
[Documentation Request] vLLM kv_load_failure_policy doesn't apply to load failures in L2 adapters Open
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
0. Needs triage bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100