GitHub Dependabot malware alerts now cover npm, PyPI and more: how to turn them on (2026)
On 28 July 2026 GitHub began ingesting OpenSSF malicious-packages advisories, so Dependabot malware alerts now cover npm, PyPI and more. Here is how to enable them and respond when one fires.