There are a few levels to consider: 1. GH provides some security feeds for their own GHE appliances 2. the projects hosted can publish their own feeds 3. a project dependencies can have vulnerabilities reported by GH
There are a few levels to consider: