> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List GitHub security advisories

> List GitHub repository security advisories for triage. Uses the GitHub App installation token — no user secrets needed. GitHub App tokens cannot use the org-wide advisory endpoint, so every request must select one repository accessible to the installation.




## OpenAPI

````yaml https://neo.api.projectdiscovery.io/api/openapi.json get /api/v1/github/security-advisories
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
  - description: >-
      Application-internal endpoints used by the Neo UI. Not part of the public
      customer API surface.
    name: Internal
paths:
  /api/v1/github/security-advisories:
    get:
      tags:
        - Internal
      summary: List GitHub security advisories
      description: >
        List GitHub repository security advisories for triage. Uses the GitHub
        App installation token — no user secrets needed. GitHub App tokens
        cannot use the org-wide advisory endpoint, so every request must select
        one repository accessible to the installation.
      operationId: get-v1-github-security-advisories
      parameters:
        - description: Neo installation UUID (from /api/v1/github/installations).
          in: query
          name: installation_id
          required: true
          schema:
            format: uuid
            type: string
        - description: >
            Repository name to list (name only, or owner/name matching the
            installation account).
          in: query
          name: repo
          required: true
          schema:
            type: string
        - description: Filter by advisory state.
          in: query
          name: state
          required: false
          schema:
            enum:
              - triage
              - draft
              - published
              - closed
            type: string
        - description: Sort property (default created).
          in: query
          name: sort
          required: false
          schema:
            enum:
              - created
              - updated
              - published
            type: string
        - description: Sort direction (default desc).
          in: query
          name: direction
          required: false
          schema:
            enum:
              - asc
              - desc
            type: string
        - description: Items per page (1-100, default 25).
          in: query
          name: per_page
          required: false
          schema:
            type: integer
        - description: Cursor for the next page (from next_cursor).
          in: query
          name: after
          required: false
          schema:
            type: string
        - description: Cursor for the previous page (from prev_cursor).
          in: query
          name: before
          required: false
          schema:
            type: string
        - description: >
            Filter by Neo triage linkage. `yes` = has a Neo triage run, `no` =
            not yet triaged in Neo, `all` (default) = no filter. When set to
            yes/no, the API scans ahead across GitHub pages to fill per_page
            matches; next_cursor may be an opaque resume cursor.
          in: query
          name: neo_triage
          required: false
          schema:
            enum:
              - all
              - true
              - false
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GitHubSecurityAdvisoriesResponse'
          description: Normalized list of security advisories.
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >
            Invalid filters, missing repo, or the GitHub App lacks the
            security-advisories permission.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unauthorized - valid authentication required.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Not authorized for this installation or repository.
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Installation not found.
        '429':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: GitHub rate limit exceeded.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Internal server error.
        '502':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: GitHub API request failed.
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    GitHubSecurityAdvisoriesResponse:
      properties:
        advisories:
          items:
            $ref: '#/components/schemas/GitHubSecurityAdvisory'
          type: array
        next_cursor:
          description: Cursor for the next page (pass as `after`).
          type: string
        prev_cursor:
          description: Cursor for the previous page (pass as `before`).
          type: string
      required:
        - advisories
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
      required:
        - error
      type: object
    GitHubSecurityAdvisory:
      properties:
        created_at:
          description: When the advisory was created (ISO 8601).
          type: string
        cve_id:
          description: Assigned CVE identifier, when available.
          example: CVE-2026-0001
          type: string
        cvss_score:
          description: CVSS base score, when available.
          example: 8.8
          format: double
          type: number
        cvss_vector:
          description: CVSS vector string, when available.
          example: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
          type: string
        description:
          description: Full advisory description, when available.
          type: string
        id:
          description: GHSA identifier.
          example: GHSA-xxxx-yyyy-zzzz
          type: string
        repo:
          description: Repository the advisory belongs to (owner/name).
          example: acme/api
          type: string
        reporter:
          description: Advisory author GitHub login, when available.
          type: string
        severity:
          description: Advisory severity rating, when set.
          example: high
          type: string
        state:
          description: Advisory state (triage, draft, published, closed, withdrawn).
          example: triage
          type: string
        title:
          description: Advisory summary.
          type: string
        triage_task:
          allOf:
            - $ref: '#/components/schemas/TriageTaskSummary'
          description: >
            Linked Neo triage run for this advisory, when one exists for your
            team. Null when triage has not been started.
          nullable: true
        url:
          description: Link to the advisory on GitHub.
          type: string
      required:
        - id
        - title
        - state
        - url
      type: object
    TriageTaskSummary:
      properties:
        completed_at:
          description: When the triage decision was recorded.
          format: date-time
          nullable: true
          type: string
        created_at:
          description: When this triage run was started or last re-triaged.
          format: date-time
          type: string
        internal_summary:
          description: >
            Team-facing triage write-up, separate from the reporter-ready reply.
            Suitable for an internal HackerOne team comment.
          nullable: true
          type: string
        suggested_response:
          description: |
            Reporter-ready reply text from Neo triage. Paste into HackerOne or
            GitHub when responding to the researcher.
          nullable: true
          type: string
        task_id:
          description: Neo task id for this triage run.
          format: uuid
          type: string
        task_status:
          description: |
            Current Neo task status for this triage run.
          enum:
            - pending
            - active
            - completed
            - error
            - aborted
            - suspended
          nullable: true
          type: string
        triage_severity:
          description: |
            Neo suggested severity. Only set when triage_status is valid;
            otherwise null.
          enum:
            - none
            - low
            - medium
            - high
            - critical
            - unknown
          nullable: true
          type: string
        triage_status:
          description: |
            Neo disposition after the triage task completed. Null while the task
            is still running or has not submitted a decision.
          enum:
            - valid
            - need_more_info
            - duplicate
            - informative
            - not_applicable
            - spam
            - unknown
          nullable: true
          type: string
        triaged_by_email:
          description: |
            Email of the team member who started or last re-triaged this run.
          nullable: true
          type: string
      required:
        - task_id
        - created_at
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````