You can use those numbers in changelogs as soon as they're published
There is some human review, which takes time, before the GHSA is "GitHub-reviewed" which then allows security scanners to pick it up
Then, the CVE ID can be assigned to it after-the-fact if need be, but the GHSA should be a sufficient starting point
You can use those numbers in changelogs as soon as they're published
There is some human review, which takes time, before the GHSA is "GitHub-reviewed" which then allows security scanners to pick it up
Then, the CVE ID can be assigned to it after-the-fact if need be, but the GHSA should be a sufficient starting point