<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/how-we-took-malware-advisories-beyond-npm-arwuoajld" -->

---
title: How we took malware advisories beyond npm | daily.dev
description: GitHub&#x27;s Dependabot has expanded malware advisory detection from npm-only to eight package ecosystems: npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and...
canonical: https://daily.dev/posts/how-we-took-malware-advisories-beyond-npm-arwuoajld
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: How we took malware advisories beyond npm | daily.dev
og:description: GitHub&#x27;s Dependabot has expanded malware advisory detection from npm-only to eight package ecosystems: npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and...
og:url: https://daily.dev/posts/how-we-took-malware-advisories-beyond-npm-arwuoajld
og:image: https://api.daily.dev/og/posts/arWuoAjld.png
og:image:alt: How we took malware advisories beyond npm
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# How we took malware advisories beyond npm

**[GitHub Blog](https://daily.dev/sources/ghblog)** · 6 min read · 0 upvotes · 0 comments

## Summary

GitHub's Dependabot has expanded malware advisory detection from npm-only to eight package ecosystems: npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. The expansion was achieved by building a single importer that ingests OpenSSF's malicious-packages repository (over 15,000 OSV-format reports) into the GitHub Advisory Database, rather than building eight separate detection systems. Key engineering challenges included normalizing ecosystem naming differences, handling version range mismatches, managing withdrawn advisories, and preventing circular re-import of GitHub's own npm advisories. The pipeline includes three security safeguards: batch caps that halt and alert on abnormal import volumes, full provenance tracing to upstream commits, and batch-level rollback capability. Malware alerts auto-publish without human review because speed matters more than nuance for active credential-stealing packages. The feature is opt-in and can be enabled in repository, organization, or enterprise security settings.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://github.blog/security/supply-chain-security/how-we-took-malware-advisories-beyond-npm>

## Questions this post answers

### Which package ecosystems does Dependabot now detect malware in, beyond npm?

Dependabot malware detection now covers eight major package ecosystems: npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This expansion was built by ingesting OpenSSF's malicious-packages repository, which stores reports in OSV format, into the GitHub Advisory Database rather than building separate detection systems for each ecosystem.

_Track dependency security coverage changes like this on daily.dev before enabling malware alerts across your stack._

### How does GitHub avoid re-importing its own npm malware reports when pulling data from OpenSSF's malicious-packages repository?

GitHub filters out any OSV record whose origin metadata is tagged 'ghsa-malware', since that tag marks reports that originated from GitHub itself and flowed upstream into the OpenSSF repo. Validation against live data showed more than half of new npm reports each month were exactly these round-trips, so skipping them ensures the importer only surfaces genuinely new threats.

_Engineers building dedup logic for third-party security feeds can follow this kind of pipeline design on daily.dev._

### What safeguards prevent a bad or malicious upstream advisory from triggering false Dependabot malware alerts?

Three layered protections guard the pipeline: batch caps that halt an entire import run and alert the team if advisory volume spikes abnormally instead of trimming to fit, provenance tracking that traces every advisory back to its exact upstream commit, and rollback capability that reverts an entire poisoned batch as one unit rather than hand-picking bad entries.

_Teams designing resilient auto-publish pipelines for security alerts can find similar engineering breakdowns on daily.dev._

## Similar posts on daily.dev

- [Dependabot alerts on malicious packages across more ecosystems](https://daily.dev/posts/dependabot-alerts-on-malicious-packages-across-more-ecosystems-erzhoartx) · GitHub Changelog · 0 upvotes · 0 comments
- [OSV Withdraws 157 Malware Reports After Automated False Posi...](https://daily.dev/posts/osv-withdraws-157-malware-reports-after-automated-false-posi--h8x7aqyaj) · Socket · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#dependabot](https://daily.dev/tags/dependabot)

[View this post on daily.dev](https://daily.dev/posts/how-we-took-malware-advisories-beyond-npm-arwuoajld)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"How we took malware advisories beyond npm","url":"https://daily.dev/posts/how-we-took-malware-advisories-beyond-npm-arwuoajld","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/how-we-took-malware-advisories-beyond-npm-arwuoajld"},"datePublished":"2026-08-06T16:51:16.662Z","dateModified":"2026-09-14T09:00:45.922Z","description":"GitHub's Dependabot has expanded malware advisory detection from npm-only to eight package ecosystems: npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7a0c2b376b38118cb2833570eee9a2f0?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7a0c2b376b38118cb2833570eee9a2f0?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"GitHub Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"GitHub Blog","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/106cf162b88840808484d4b5429b59b1","url":"https://daily.dev/sources/ghblog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/how-we-took-malware-advisories-beyond-npm-arwuoajld","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,dependabot","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"GitHub Blog","item":"https://daily.dev/sources/ghblog"},{"@type":"ListItem","position":3,"name":"How we took malware advisories beyond npm"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/how-we-took-malware-advisories-beyond-npm-arwuoajld#faq","mainEntity":[{"@type":"Question","name":"Which package ecosystems does Dependabot now detect malware in, beyond npm?","acceptedAnswer":{"@type":"Answer","text":"Dependabot malware detection now covers eight major package ecosystems: npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This expansion was built by ingesting OpenSSF's malicious-packages repository, which stores reports in OSV format, into the GitHub Advisory Database rather than building separate detection systems for each ecosystem. Track dependency security coverage changes like this on daily.dev before enabling malware alerts across your stack."}},{"@type":"Question","name":"How does GitHub avoid re-importing its own npm malware reports when pulling data from OpenSSF's malicious-packages repository?","acceptedAnswer":{"@type":"Answer","text":"GitHub filters out any OSV record whose origin metadata is tagged 'ghsa-malware', since that tag marks reports that originated from GitHub itself and flowed upstream into the OpenSSF repo. Validation against live data showed more than half of new npm reports each month were exactly these round-trips, so skipping them ensures the importer only surfaces genuinely new threats. Engineers building dedup logic for third-party security feeds can follow this kind of pipeline design on daily.dev."}},{"@type":"Question","name":"What safeguards prevent a bad or malicious upstream advisory from triggering false Dependabot malware alerts?","acceptedAnswer":{"@type":"Answer","text":"Three layered protections guard the pipeline: batch caps that halt an entire import run and alert the team if advisory volume spikes abnormally instead of trimming to fit, provenance tracking that traces every advisory back to its exact upstream commit, and rollback capability that reverts an entire poisoned batch as one unit rather than hand-picking bad entries. Teams designing resilient auto-publish pipelines for security alerts can find similar engineering breakdowns on daily.dev."}}]}
```

