megachangelog
Feature

Dependabot alerts on malicious packages across more ecosystems

GitHub Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, expanding the breadth of malware detection available through Dependabot alerts across more package ecosystems.

The GitHub Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, significantly expanding the breadth of malware data available to you through Dependabot alerts.

What changed

With this update, advisories from the OpenSSF malicious-packages project are automatically ingested into the GitHub Advisory Database, giving you broader coverage across ecosystems including npm, PyPI, and more. You can view these using the type:malware filter.

If you have malware alerting enabled, Dependabot will now match your dependencies against this expanded set of malware advisories and alert you when a match is found.

What this means for you

You get broader ecosystem coverage. Malware advisories now cover additional ecosystems beyond npm, powered by the OpenSSF community’s malicious-packages data.

If you already have malware alerting enabled, you will automatically benefit from the expanded coverage without any additional configuration needed. New advisories will generate alerts as they are published.

Getting started

If you haven’t enabled malware alerting yet, navigate to your repository or organization Settings → Code security → Dependabot and enable Malware alerts under the Dependabot alerts section.

You can browse malware advisories directly at github.com/advisories.

To learn more, check out our docs about Dependabot malware alerts.

The post Dependabot alerts on malicious packages across more ecosystems appeared first on The GitHub Blog.

dependabotsecuritymalwareadvisoriessupply-chain

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →