As mentioned by another commenter, they intentionally have a human reviewer in the process before a GitHub Security Advisory (GHSA) becomes "official" post-publish
(this is separate to getting CVE ID assigned, if wanted)
As mentioned by another commenter, they intentionally have a human reviewer in the process before a GitHub Security Advisory (GHSA) becomes "official" post-publish
(this is separate to getting CVE ID assigned, if wanted)