Dependabot alerts on malicious packages across more ecosystems - GitHub Changelog
…What changed With this update, advisories from the OpenSSF malicious-packages project are automatically ingested into the GitHub Advisory Database , giving you broader coverage across ecosystems including npm, PyPI, and more. You…