Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

GitHub now publishes malware advisories in the GitHub Advisory Database

Blog post from GitHub

Post Details
Company
Date Published
Author
Brittany O'Shea, Kate Catlin
Word Count
262
Company Posts That Month
40
Language
English
Hacker News Points
-
Post removed?
No
Summary

Vulnerabilities in open source software are primarily caused by mistakes, but malicious actors can also introduce malware, which is typically removed and not included in the standard disclosure process like the National Vulnerability Database. GitHub employs automated scanning, security research, and community input to detect such malware, and now documents these incidents in the GitHub Advisory Database after removal. This database supports GitHub’s supply chain security features, including Dependabot alerts, which notify users of malware and vulnerabilities. Users can enable these alerts under the "Code security and analysis" tab. The GitHub Advisory Database, providing security advisories that enhance GitHub's supply chain security solutions, has been freely available and licensed under Creative Commons, ensuring ongoing community access and use.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.