GitHub · OFFICIAL ARTICLE

Dependabot 警报覆盖更多生态系统的恶意软件包

GitHub Advisory Database 现已接入 OpenSSF malicious-packages 仓库的恶意软件公告,显著扩充了 Dependabot 警报中可用的恶意软件数据范围。本次更新内容包括……

来源:GitHub
ORIGINAL · 官方原文

Dependabot alerts on malicious packages across more ecosystems

详细说明

Back to changelog

-

What changed

-

What this means for you

-

Getting started

The GitHub Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, significantly expanding the breadth of malware data available to you through Dependabot alerts.

What changed

With this update, advisories from the OpenSSF malicious-packages project are automatically ingested into the GitHub Advisory Database , giving you broader coverage across ecosystems including npm, PyPI, and more. You can view these using the type:malware filter.

If you have malware alerting enabled , Dependabot will now match your dependencies against this expanded set of malware advisories and alert you when a match is found.

What this means for you

You get broader ecosystem coverage. Malware advisories now cover additional ecosystems beyond npm, powered by the OpenSSF community’s malicious-packages data.

If you already have malware alerting enabled, you will automatically benefit from the expanded coverage without any additional configuration needed. New advisories will generate alerts as they are published.

Getting started

If you haven’t enabled malware alerting yet, navigate to your repository or organization Settings → Advanced security → Dependabot and enable Malware alerts under the Dependabot alerts section.

You can browse malware advisories directly at github.com/advisories .

To learn more, check out our docs about Dependabot malware alerts .

-

What changed

-

What this means for you

-

Getting started

Share

Copied

Shared

Back to changelog