GitHub's 2025 open source security data reveals 4,101 reviewed advisories (a four-year low), but the drop reflects fewer old vulnerabilities being backfilled rather than improved security. Newly reported vulnerabilities actually grew 19% year over year. npm malware advisories surged 69% due to large campaigns like SHA1-Hulud.

7m read timeFrom github.blog
Post cover image
Table of contents
What is the GitHub Advisory Database?How vulnerabilities were distributed across ecosystems in 2025How the types of vulnerabilities changed in 2025How to prioritize your responseCVE publicationsOrganizations using GitHub’s CNATags:Written by

Sort: