The GitHub Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, significantly expanding the breadth of malware data available to you through Dependabot alerts.

What changed

With this update, advisories from the OpenSSF malicious-packages project are automatically ingested into the GitHub Advisory Database, giving you broader coverage across ecosystems including npm, PyPI, and more. You can view these using the type:malware filter.

If you have malware alerting enabled, Dependabot will now match your dependencies against this expanded set of malware advisories and alert you when a match is found.

What this means for you