| CARVIEW |
- Resources
- Open Source Community
- Enterprise
Securing open source software, together
Enhance security by fostering global collaboration.
We do the hard work, you can use it.
Dive into security research on open-source projects to explore new and emerging threats, and learn how to mitigate them so that you can make your own software more secure.
Read the Research
Latest vulnerabilities disclosed
-
Code injection in vets-apiGHSL-2025-105 • published 2025/12/19 00:00:00 ago • Peter Stöckli
-
Code injection in acl-anthologyGHSL-2025-102_GHSL-2025-103 • published 2025/12/19 00:00:00 ago • Peter Stöckli
-
Code Injection in esphome/esphome-docs Github Actions WorkflowGHSL-2025-106 • published 2025/12/11 00:00:00 ago • Man Yue Mo
-
Cross-site scripting (XSS) in OpenLibrary barcode scannerGHSL-2025-110 • published 2025/12/04 00:00:00 ago • Peter Stöckli
-
Cross-site scripting (XSS) in bit platform Boilerplate WebInteropApp - CVE-2025-64710
Join us in our mission to improve open source security for all
Have you used CodeQL’s variant analysis to find vulnerabilities on open source projects? Give your work the visibility it deserves by submitting your finding for the CodeQL Wall of Fame.
Share your workOpen doors, open solutions:
Embracing Enterprise & Open Source
Contributions from maintainers, developers, and security researchers around the world push us forward, making the open source software a better place.
Open Source Community
Learn about secure coding practices, get hands-on with AppSec training, and connect with experts during our office hours – free for open source developers, maintainers, and security researchers.
GitHub Security Lab for the Enterprise
At the GitHub Security Lab, our security experts, through community collaboration, strengthen open source security which is crucial for enterprises. We channel the community’s contributions into proven CodeQL queries and timely security advisories, and offer enterprises actionable insights that help secure your supply chain and accelerate the software development lifecycle.
About the GitHub Security Lab.
Learn more on GitHub Security Lab
Through research, education, and maintenance of the GitHub Advisory Database, we empower the community.
We’re active on social media!
Through research, education, and maintenance of the GitHub Advisory Database, we empower the community.