The Signal
Retained coverage centers on GitHub expanding Dependabot malware alerts beyond npm, addressing a prior warning gap for users of other package ecosystems. [1]
Must Know
Dependabot malware-alert coverage expansion
What happened
GitHub’s Dependabot malware alerts previously monitored npm data alone, according to the source. [1]
The source states that Dependabot malware alerts were expanded to cover eight ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer in addition to npm. [1]
Why it matters
Before the change, the source says users pulling malicious packages from the other named ecosystems received no warning from GitHub’s malware detection. [1]