Better GHSA
Overview
Triage state for GitHub security advisories, kept in a comment on the advisory.
A Firefox and Chrome extension that adds triage tracking to GitHub Security Advisories for the maintainers who work them. A repository's security advisories arrive as private reports and stay private while maintainers decide what to do with them. GitHub gives each advisory a state (triage, draft, published, closed), a severity, and a comment thread. It does not give a place to record who owns the report, whether anyone has checked the title and the score the reporter proposed, which release branches need a backport, whether an embargo applies and when it lifts, or why an advisory was closed. Maintainers keep that in their heads, in chat, or nowhere. This extension keeps it on the advisory. Each maintainer's triage state is written into a comment on the advisory itself: one comment per maintainer per advisory, created on that maintainer's first save and edited on every save after that. The comment is a collapsed <details> block holding a JSON snapshot. The extension reads every maintainer's state comment on an advisory and merges them into one current state. There is no server and no database. Nothing is synchronized between browsers. An advisory carries its own state. One maintainer can use the extension while the others work through GitHub's own interface, and a maintainer who uninstalls it loses nothing that was saved. The reporter of an advisory can read the whole thread, state comments included. The vocabulary the extension uses is written to be read that way: nothing is encoded or obfuscated. Saving posts or edits a comment. Posting notifies the advisory's participants, the reporter among them. The extension keeps a local cache so pages draw immediately. The cache is never authoritative and is always rebuildable by re-reading the advisories. The advisory detail panel sits on an advisory page. It shows what the extension derived from the page (patch progress in the private fork, CVE state, how long the advisory has been waiting, whether anyone has reviewed it), shows and edits the stored triage state, and offers a button that preserves the reporter's original title and description in a comment before maintainers rewrite them for publication. The advisory list replaces the body of a repository's advisory list with a table of open advisories, ordered so that the ones needing attention are at the top, with chips for waiting state, patch progress, confirmations, CVE, severity, and embargo, and with filters and sorts over them. A toggle restores GitHub's own view. The completed view lists published and closed advisories and records a closure reason on each, including retroactively on advisories closed before the extension existed. A statistics view sits beside it with counts and response timings over the whole corpus and a CSV export.
0 out of 5No ratings
Details
- Version0.0.1
- UpdatedSeptember 2, 2026
- Offered bySamuel Karp
- Size200KiB
- LanguagesEnglish (United States)
- Developer
Email
better-ghsa@sbk.wtf - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
Better GHSA has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
Better GHSA handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site