The GitHub Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, significantly expanding the breadth of malware data available to you through Dependabot alerts.
What changed
With this update, advisories from the OpenSSF malicious-packages project are automatically ingested into the GitHub Advisory Database, giving you broader coverage across ecosystems including npm, PyPI, and more. You can view these using the type:malware filter.
If you have malware alerting enabled, Dependabot will now match your dependencies against this expanded set of malware advisories and alert you when a match is found.
What this means for you








