Nvidia shifts security bulletins to GitHub but website availability remains unclear
Starting October 1, 2026, Nvidia’s Product Security Incident Response Team (PSIRT) will publish security bulletins exclusively on GitHub in Markdown, CSAF, and CVE formats. The company states this change meets industry demand for easier integration of security advisories. However, Nvidia also claims that all bulletins will remain available on its Product Security website, ensuring parallel access from both sources.
The confusion arises because Nvidia’s GitHub repository does not mention the continued availability of bulletins on its website. The repository’s README only states that bulletins will be published on GitHub, omitting any reference to the Product Security website running in parallel. This discrepancy leaves customers unsure about which source to rely on for authoritative information.
Since the deadline, two new bulletins have been published on GitHub, dated October 6. These include bulletin 5891 for TensorRT and bulletin 5903 for Nvidia’s Model-Optimizer, each addressing a single CVE. The repository currently holds bulletins from 2022 onward, with older ones being added gradually. Meanwhile, the Product Security page maintains an archive of bulletins dating back to 2018.
Nvidia has not clarified which copy of a bulletin it considers authoritative if discrepancies arise between the GitHub repository and the Product Security website. This uncertainty may affect users who rely on these advisories for security updates, particularly those managing large-scale deployments of Nvidia products.