Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

How we took malware advisories beyond npm

Blog post from GitHub

Post Details
Company
Date Published
Author
Ankit Kumar Honey
Word Count
1,129
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitHub has expanded Dependabot malware advisories from npm to eight package ecosystems—npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer—by ingesting reports from OpenSSF’s public malicious-packages repository. Rather than build separate detection systems for each ecosystem, GitHub created an importer that validates OSV-format reports, normalizes package and version data, preserves source records, processes withdrawals, and avoids re-importing GitHub’s own advisories through origin metadata. Because malware reports must be published quickly to protect users, the resulting advisories can automatically generate Dependabot alerts without prior human review, unlike many conventional vulnerability advisories. To reduce the risks of incorrect or compromised upstream data, the pipeline uses configurable batch limits, commit-level provenance tracking, and batch-wide rollback capabilities. Malware alerts are opt-in and can be enabled at repository, organization, or enterprise level, whereupon Dependabot checks both current dependencies and existing advisories for malicious packages.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.