GitHub Changelog
7/28/2026

The original headline is: "Dependabot alerts on malicious packages across more ecosystems"
Original: Dependabot alerts on malicious packages across more ecosystems
Short summary
GitHub's Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, expanding Dependabot alert coverage to more ecosystems. This gives developers broader visibility into malicious package threats across their dependency trees. The change strengthens supply-chain security monitoring for GitHub users.
- •Dependabot now pulls malware advisories from OpenSSF malicious-packages repo
- •Expands alert coverage across more package ecosystems
- •Improves supply-chain security visibility for developers
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



