How we took malware advisories beyond npm

GitHub Version 1 original current

Imported from official source

GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid. The post How we took malware advisories beyond npm appeared first on The GitHub Blog.

This version

Version
1 of 1
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
e03212928a36837267a70b838d43bdf7
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.