Dependabot alerts on malicious packages across more ecosystems
The GitHub Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, significantly expanding the breadth of malware data available to you through Dependabot alerts.
Read GitHub's release noteshttps://github.blog/changelog/2026-07-28-dependabot-alerts-on-malicious-packages-across-more-ecosystems
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
npm publish-time malware scanning and dual-use metadata
UpdateGovernanceSecurityObservability
CodeQL 2.26.1 improves analysis accuracy and framework coverage
UpdateSQLSecurityObservability
Code coverage automatic enablement in Code Quality settings
PreviewAI agentsSecurityData integration
CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support
UpdateSQLGovernanceSecurity
Also shipped on Jul 28, 2026
Python UDTFs in Unity Catalog are now generally available
GASQLGovernanceObservability
Vercel Connect now supports Custom Environments
PreviewPricingData integrationBI