DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Topics
Follow your own topics →
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

github: Dependabot alerts on malicious packages across more ecosystems

1 · Sujith Quintelier · July 29, 2026, 6:04 a.m.
malware Dependabot Software Security OpenSSF
Summary
GitHub's Advisory Database has enhanced Dependabot alerts by incorporating malware advisories from OpenSSF's repository, thereby expanding safety measures across various ecosystems.
Read full post on quintelier.dev →
MORE POSTS LIKE THIS
Massive PyPI Supply Chain Attack Staged via Malware Startup Hooks
Securityonline · Jun 7, 2026
malware Bun runtime
Dissecting the JWR phishing framework
Blog Talosintelligence · Aug 13, 2026
Threat Spotlight Phishing
Security Baked Into the JVM: two Subjects, one call
nfrankel · Aug 9, 2026
Java jvm
security: From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
Sujith Quintelier · Aug 6, 2026
Security macos
npm supply-chain attack hits 400+ packages and steals developer credentials
Developer Tech · Aug 6, 2026
CI/CD & Release Engineering Cybersecurity & Development
Investigating three real-world incidents in our cybersecurity evaluations
simonw · Jul 31, 2026
pypi Python
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google