How we took malware advisories beyond npm
Blog post from GitHub
GitHub has expanded Dependabot malware advisories from npm to eight package ecosystems—npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer—by ingesting reports from OpenSSF’s public malicious-packages repository. Rather than build separate detection systems for each ecosystem, GitHub created an importer that validates OSV-format reports, normalizes package and version data, preserves source records, processes withdrawals, and avoids re-importing GitHub’s own advisories through origin metadata. Because malware reports must be published quickly to protect users, the resulting advisories can automatically generate Dependabot alerts without prior human review, unlike many conventional vulnerability advisories. To reduce the risks of incorrect or compromised upstream data, the pipeline uses configurable batch limits, commit-level provenance tracking, and batch-wide rollback capabilities. Malware alerts are opt-in and can be enabled at repository, organization, or enterprise level, whereupon Dependabot checks both current dependencies and existing advisories for malicious packages.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.