Skip to content
GAdvisory

How GAdvisory works

Reference documentation for the product: what it does, how it differs from the alternatives, what it takes to run, and what it means to operate as a numbering authority. Written for somebody deciding whether to adopt it, and kept accurate for somebody already running it.

Documentation

Start here

The product

The hierarchy, the advisory editor, identifiers, the six places an advisory is published, and what it takes to keep running.

Running it yourself

What a host has to provide, where secrets live, how upgrades behave, and how to get your data out.

Air-gapped and regulated

What works with no network at all, and the evidence a disclosure process is normally asked to produce.

CNA and GNA operations

Requesting CVEs, minting GCVE identifiers under your own remit, and the approval gate around anything irreversible.

GAVR, the record format

Per-container signatures, registry countersignature, offline verification, and why the specification is published under an open licence.

How it compares

GitHub, GitLab and the VDP platforms, including where each of them is the better choice.

© 2026 Gelhaus Solutions