Our mission
Securing the open source supply chain.
Threat Navigator is a security research initiative that identifies,
verifies, and reports vulnerabilities in open source dependencies
and tooling.
01
Identify
Automated systems continuously scan GitHub for actively
maintained projects with a security program in place, flagging
code patterns that indicate a potential vulnerability.
02
Verify
Every flagged finding is reviewed by a collaborating security
engineer, who reproduces and confirms real-world
exploitability before it goes any further.
03
Report
Confirmed vulnerabilities are responsibly disclosed to
maintainers. Once public, the report is tracked below.
Raised Vulnerabilities
Findings verified by our security engineers, published as GitHub
Security Advisories.
The Navigator
Every vulnerability we raise is cross-referenced against the
frameworks security teams already use — so tracing from a weakness
to an adversary technique to a countermeasure doesn't mean four
separate tabs.
CWE
The underlying software weakness — what went wrong in the code.
CAPEC
The attack pattern — how that weakness is exploited in practice.
ATT&CK
The adversary technique — where it fits in a real intrusion.
D3FEND
The countermeasure — what actually stops or detects it.
On GHSA vs. CVE: GitHub Security Advisories are
frequently published weeks before NVD assigns a CVE identifier.
Rather than wait, the Navigator treats GHSAs as first-class
entries — every advisory gets its own page, cross-referenced
against the same frameworks, with the CVE linked in
automatically once one is assigned.