GitHub Advisory Database now tracks malicious packages beyond npm using OpenSSF data. The new automated ingestion pipeline flags supply chain threats across multiple ecosystems to protect developers. This integration gives AI developers and maintainers centralized visibility into third-party risks directly inside their standard dependency workflows.
Opening Kapyn…