Threat Navigator

Our mission

Securing the open source supply chain.

Threat Navigator is a security research initiative that identifies, verifies, and reports vulnerabilities in open source dependencies and tooling.

01

Identify

Automated systems continuously scan GitHub for actively maintained projects with a security program in place, flagging code patterns that indicate a potential vulnerability.

02

Verify

Every flagged finding is reviewed by a collaborating security engineer, who reproduces and confirms real-world exploitability before it goes any further.

03

Report

Confirmed vulnerabilities are responsibly disclosed to maintainers. Once public, the report is tracked below.

Raised Vulnerabilities

Findings verified by our security engineers, published as GitHub Security Advisories.