Skip to content

License data quality improvements

UpdateVerifiedAdded Sep 22, 2026

GitHub now uses package registries like npmjs.org and PyPI to determine license information for software components in the dependency graph. This improves the accuracy and completeness of the licenses shown in dependency insights, software bills of materials (SBOMs), the open source license compliance feature in GitHub Advanced Security, and the dependency...

Read GitHub's release notes

https://github.blog/changelog/2026-08-13-license-data-quality-improvements

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

Track organization code quality trends

GA

Secret scanning coverage updates

Update

Customize code scanning default setup at scale

Update

Customize Dependabot pull request branch names

Update

Code coverage automatic enablement in Code Quality settings

Preview

Also shipped on Aug 13, 2026

Weekly: the week's data and AI releases, Tuesday mornings.