As cited
Copy frozen at (site build).
cloud saas
GitHub Dependabot malware alerts now cover eight ecosystems
GitHub extended its Dependabot malware detection from npm packages to cover seven additional ecosystems: PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. The expansion leverages OpenSSF's malicious-packages repository, which tracks over 15,000 malicious packages including typosquats and dependency-confusion attacks. Developers across these ecosystems now receive alerts when pulling in known malicious dependencies.
Why it matters: Developers in Python, Java, Ruby, .NET, Go, Rust, and PHP projects benefit from earlier detection of malicious dependencies; practitioners should verify that Dependabot alerts are configured and reviewed in projects using these package managers.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
GitHub Dependabot malware alerts now cover eight ecosystems
GitHub extended its Dependabot malware detection from npm packages to cover seven additional ecosystems: PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. The expansion leverages OpenSSF's malicious-packages repository, which tracks over 15,000 malicious packages including typosquats and dependency-confusion attacks. Developers across these ecosystems now receive alerts when pulling in known malicious dependencies.
Why it matters: Developers in Python, Java, Ruby, .NET, Go, Rust, and PHP projects benefit from earlier detection of malicious dependencies; practitioners should verify that Dependabot alerts are configured and reviewed in projects using these package managers.
- Source published
- First seen by Cybersecurity Tracker