Advisory

Advisory: A way to flag the usage of a given package as potentially risky, or at least requiring review.

Advisories are a great way to get insight into packages that are being used and flag cases where packages in use may not be wanted.

For instance, by generating advisories, we can get insight into:

As noted in Using custom Advisories to flag packages in use, it's also possible to add your own advisories to flag packages that your organisation may not want to use, highlight versions of internal libraries that have security issues, and many other possibilities.

You can see the supported types of advisories defined in the database schema for the advisories or custom_advisories tables table.

Note that other tables are used for generating and determining advisories other than the advisories table.