Very recently Github's graphql API started providing for vulnerabilities for go packages. We need to ingest this as part of the github importer There's also very recent https://github.com/golang/vulndb