Vulnerability management meets GitHub Advanced Security
GitHub Advanced Security (GHAS) gives development teams a security overview dashboard for tracking coverage across repositories and spotting the ones that need attention first. For security teams that also need to consolidate findings from multiple sources, automate risk workflows, and see GitHub alerts inside their broader security tooling, GitHub has announced new integrations with four vulnerability management providers: Brinqa, Kenna Security, Nucleus, and Threadfix.
These integrations connect GHAS alert data into platforms that prioritize software vulnerabilities and help organizations reduce business risk. If your preferred tool is not among the four, GitHub has published a detailed integration guide that covers how to replicate these connections. Vulnerability management vendors interested in building a similar integration can also apply to the technology partner program.
Brinqa: Attack surface intelligence

Brinqa coordinates the end-to-end cyber risk lifecycle: understanding the attack surface, ranking vulnerabilities, driving remediation, and monitoring security posture across on-premises systems, cloud, and applications. Its Attack Surface Intelligence Platform acts as a central source of truth for cyber risk, helping organizations track vulnerabilities, assign accountability to risk owners, identify gaps in security control coverage, and manage findings through a single cloud-based console. The GitHub connector is available on Brinqa's connector page.
Kenna Security: Risk-based prioritization in CI/CD

Kenna Security is a risk-based vulnerability management SaaS platform that applies machine learning to rank vulnerabilities according to actual risk. It pulls data from web application scanners, network scanners, and software composition analysis tools, among others. GitHub Actions make it possible to feed code scanning, Dependabot, and secret scanning alerts into Kenna from your CI/CD pipeline (see the Kenna-Actions repository). A distinguishing capability is risk scoring based on real-world exploit data and predictive models, which helps security teams focus remediation effort where it matters most.
Nucleus: Real-time context for app vulnerabilities

Nucleus is a cloud-based vulnerability management platform that unifies asset and vulnerability information from more than 100 native integrations, including network scanners, application scanners, code repositories, asset inventories, and endpoint detection tools. The GitHub integration exposes application vulnerabilities across all GitHub organizations, teams, repositories, and branches. The platform also measures remediation effectiveness through reports and analytics, and brings real-time threat intelligence in-platform so teams can respond to newly emerging threats without switching tools.
ThreadFix: Closing the loop to remediation

ThreadFix is an application vulnerability management platform with over a decade of production use among Fortune 500 companies. It integrates with dozens of scanners and analysis tools, plus native support for developer defect tracking systems. A GitHub Action for uploading code scanning results to ThreadFix lets you push findings from GitHub into ThreadFix directly. The platform manages the full AppSec lifecycle from discovery through remediation, and ingesting findings into ThreadFix reduces the number of code issues that require manual triage — a meaningful efficiency gain for large enterprises.



