Fixed
Project:
Drupal Security Team
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
14 Jul 2026 at 15:56 UTC
Updated:
29 Sep 2026 at 23:48 UTC
Jump to comment: Most recent
It would be nice to have the advisory data as csv to use in places like spreadsheets and so we can do analysis and try to identify trends.
I think we want to go back as far as https://www.drupal.org/sa-core-2018-001 which is maybe the most modern one that has multiple vulnerabilities in a single advisory and is therefore a bit messy to analyze. We may want to try to clean those up some day.
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
gregglesI built this initially a while ago for Drupalcon Chicago using a mix of gemini and my work. Then recently I polished it up with a mix of Claude and my work.
The data back to 2018 seems to work well. That's about 680 advisories currently.
I use the command
csvcut -c 1,2,3,4,5,6,7,8,9,10 drupal_sa_report.csv | uniqto get data about just unique the advisories without information about the people involved. csvcut is part of csvkit https://github.com/wireservice/csvkitComment #6
gregglesOkeydoke.