npm publish-time malware scanning and dual-use metadata
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time . This changelog covers what publishers can expect and a new metadata requirement for dual-use content.
Read GitHub's release noteshttps://github.blog/changelog/2026-07-28-npm-publish-time-malware-scanning-and-dual-use-metadata
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Dependabot alerts on malicious packages across more ecosystems
UpdateSecurityData integration
CodeQL 2.26.1 improves analysis accuracy and framework coverage
UpdateSQLSecurityObservability
Code coverage automatic enablement in Code Quality settings
PreviewAI agentsSecurityData integration
CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support
UpdateSQLGovernanceSecurity
Also shipped on Jul 28, 2026
Python UDTFs in Unity Catalog are now generally available
GASQLGovernanceObservability
Vercel Connect now supports Custom Environments
PreviewPricingData integrationBI