GitHub broadens Dependabot defence against malicious packages
GitHub has expanded Dependabot malware alerts across major open-source package ecosystems, widening automated protection against compromised and deliberately malicious software dependencies beyond the npm registry. The change gives developers earlier warnings when projects depend on packages identified as malware. The expanded coverage is powered by the GitHub Advisory Database importing…
GitHub has expanded its Dependabot malware alerts to cover major open-source package ecosystems beyond the npm registry. This enhancement provides developers with earlier warnings when projects depend on compromised or malicious software dependencies. The expanded coverage is made possible by importing malicious-package intelligence from the OpenSSF Malicious Packages project into the GitHub Advisory Database, which then feeds the records directly into Dependabot.
This integration allows Dependabot to compare dependencies used in participating repositories with the malicious-package records, creating alerts when a match is found. OpenSSF’s repository contains malicious-package records spanning a wide range of package sources, including npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and Packagist, covering a significant portion of modern JavaScript, Python, Java, Ruby, .NET, Go, Rust, and PHP development.
With this update, repositories that already have malware alerting enabled will automatically receive the broader coverage, and administrators do not need to modify their existing Dependabot configurations. New malware advisories are evaluated against dependencies as they enter the advisory database, while organizations that have not activated the feature can enable malware alerts through their repository or organization security settings.
Brief written by urgent.news from Arabian Post's own syndicated text. Machine-written — it may contain errors, so check the original before relying on it.