Follow the latest coverage, related explainers and connected technology stories.
The GitHub Advisory Database now imports malicious package data from the OpenSSF repository, enabling Dependabot to issue alerts across eight package ecosystems instead of being limited to npm. The new system relies on automated validation, source tracking, import limits, and rollback capabilities to protect the database from incorrect or compromised data.