Dispatch
GitHub extends malware advisories to eight ecosystems and admits half of npm reports were its own echo
Announced August 6, GitHub wired the OpenSSF malicious-packages repository — over 15,000 OSV-format reports since its 2023 launch — into the Advisory Database, expanding malware advisories from npm alone to npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and Composer. Because malware advisories auto-publish without human review, the pipeline is built "paranoid": per-run batch caps that halt rather than partially proceed, provenance back to the exact upstream commit, and batch-level rollback. The disclosure buried in the post: human deduplication found more than half of new npm reports flowing into OpenSSF each month originated from GitHub's own prior advisories.
Source
↳ Follow the thread