A signature using at auditing is changeable. So we should do signature versioning or entire advisory-db versioning by git tag (for example).