Concept and mechanism
An advisory describes a known problem and can include affected versions, available fixes, and classifications. CVE identifies a vulnerability, GHSA identifies a GitHub advisory, and CWE describes a weakness class; they are not interchangeable risk scores. Distinguish a fixable vulnerability from a package classified as malware across every version: simply seeking the latest version does not resolve the latter case. Prioritize using severity, exposure, likely exploitation, actual use, and service impact. Production data helps when it connects the delivered artifact to code and dependencies; stale or incomplete data needs to be identified as such. A decision record should explain why work is urgent or deferred.
Guided application
In a fictional committee, a campaign with eighty closed alerts can contain thirty fixes and fifty dismissals. Present those outcomes separately with reasons, owners, and residual risk. Capacity shortage does not turn a vulnerability into a false positive. An exception should have suitable authority, conditions, a deadline, and reassessment. Code-scanning dismissal applies to the alert across branches and can be reversed; its effect exceeds changing a personal filter. Use the campaign to track progress and unblock teams while preserving evidence of fixes and decisions not to fix. The aggregate percentage should support decisions without replacing an account of what was actually delivered.
30 fixed and 50 dismissed: communicate 30 fixes and 50 reasoned decisions, not 80 fixes.
Common pitfalls
Closed as fixed; CVSS as sole context; no patch as no risk; capacity shortage as false positive.
Related topics: Products, scope, and prevention · Credentials, response, and exceptions · Dependencies, inventory, and merge prevention
Distinguish technical risk reduction, risk acceptance, and remaining work.
Reference: Campaign tracking · GH-500 skills measured July2026;study guide updated2026-05-14