There's a project similar to this one that is doing per-CVE searches on Github. Our choice here is to either
- add those searches directly ourselves. Their process appears to be:
- Get vul IDs from NVD
- Search github for each vul ID
I haven't looked in detail to see if/how often they recheck older IDs.
- write a workflow and tool that
Of the two of these, item 2 seems the easier one to incorporate, although certainly 1 is more robust to future change.