# GitHub Security Advisory Changes Feed

> GitHub Security Advisory Changes Feed is a paid API for AI agents from oracles-production.up.railway.app, paid per call via x402, $0.05/call, status unknown (last checked 2026-09-15).

Returns GitHub security advisories (GHSAs) published since a given timestamp, each scored by severity with affected package details and source links.

## Facts

- Endpoint: GET https://oracles-production.up.railway.app/v1/ghsa/changes
- Price: $0.05/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-15
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/github-security-advisory-changes-feed-a666dd91
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap__7geZu2WPBeS6IkjU7Zyr

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability github-security-advisory-changes-feed-a666dd91
```

Example prompt: Pull all GitHub security advisories detected since 2025-01-01T00:00:00Z with a significance score of at least 7, up to 100 results, so I can review critical open-source vulnerabilities from this year.

## When to prefer this

Use this endpoint when you need a time-bounded, severity-filtered feed of GitHub Security Advisories with structured metadata and direct verification links — particularly for automated security monitoring pipelines, vulnerability triage workflows, or alerting systems that need to track new CVEs and GHSAs as they are published. Prefer this over raw GitHub API calls when you want pre-scored significance ratings and a clean change-feed format.

## Known failure modes

- Invalid date-time format for 'since' parameter returns 400 validation error
- min_significance out of range (below 1 or above 10) returns 400
- limit exceeds 500 returns 400
- No advisories found in the time window returns empty changes array with count 0
- Payment not included or rejected returns 402 Payment Required
- Upstream GitHub Advisory Database unavailable returns 503 or timeout

## How this service works

New security vulnerabilities and CVEs across all software ecosystems published since a timestamp (GitHub's reviewed advisory database) — each with its CVE ID, CVSS/severity score, affected package names, and a link. Answers "did a dependency I use get a new CVE or vulnerability I should patch?"

## Output

A JSON object containing a count, source label, and an array of advisory change objects — each with GHSA ID, title, summary, severity significance score (1–10), affected package details, a primary source URL for verification, the detection timestamp, and optional effective date.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {
      "limit": {
       "type": "integer",
       "maximum": 500,
       "minimum": 1
      },
      "since": {
       "type": "string",
       "format": "date-time",
       "description": "Only changes detected after this ISO-8601 instant"
      },
      "min_significance": {
       "type": "integer",
       "maximum": 10,
       "minimum": 1,
       "description": "Keep only changes scored at least this"
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object",
     "properties": {
      "count": {
       "type": "integer"
      },
      "source": {
       "type": "string"
      },
      "changes": {
       "type": "array",
       "items": {
        "type": "object",
        "properties": {
         "type": {
          "type": "string"
         },
         "title": {
          "type": "string"
         },
         "detail": {
          "type": "object"
         },
         "summary": {
          "type": "string"
         },
         "entityId": {
          "type": "string"
         },
         "sourceUrl": {
          "type": [
           "string",
           "null"
          ],
          "description": "Primary-source link for verification"
         },
         "detectedAt": {
          "type": "string",
          "format": "date-time"
         },
         "significance": {
          "type": "integer",
          "maximum": 10,
          "minimum": 1
         },
         "effectiveDate": {
          "type": [
           "string",
           "null"
          ]
         }
        }
       }
      }
     }
    }
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/github-security-advisory-changes-feed-a666dd91/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from oracles-production.up.railway.app](https://www.zero.xyz/host/oracles-production.up.railway.app/llms.txt)
