Security1 distinct publisher2 min readPublished
The engineer running Dependabot across 30 million repositories says wiring in OpenSSF's malicious-package feed was the cheap part, while normalization ate the budget and each alert ends in a build-credential incident.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Multiply the daily npm rate by 365 and the twelve months to May 2026 produced on the order of 6,570 catalogued malicious packages in a single ecosystem [4][18]. That figure is why the GitHub engineer who leads the Dependabot team, writing at Help Net Security, calls per-record human review theater. It cannot scale. It also relocates alert fatigue from users into an internal queue that quietly backs up [19][15].
The control sits somewhere else. Upstream sources publish mistakes, including reports that land on the wrong package name and bulk imports that go sideways overnight [11]. His requirement is that every ingested record keeps a trail back to the exact upstream change that produced it, that imports revert as a batch in one move in minutes, and that provenance is treated as an operational control on the same shelf as feature flags and rollbacks [10]. He also cites a cap on how many advisories a single input can generate, though the text available breaks off mid-sentence before naming the unit [16].
Eight ecosystems is where the judgement calls pile up. Registries disagree on whether package names are case-sensitive. Affected versions arrive as exact pins in one format and open-ended ranges in another, and the boundary semantics differ just enough to hurt. Severity vocabularies do not line up either [9]. A consumer inherits all of that: the database was built by someone else's processes, shaped by someone else's judgement calls, and the automation simply acts on what it is handed [20].
GitHub sits on both sides of that exchange. It had been flagging npm malware since March, per the author, before extending coverage [3], which makes it a contributor to the commons it now reads from, and community repositories strip the context of who found what first [12].
The author argues the same lessons hold whether the input is package malware reports, OSV records, or ISAC indicators [17]. That generalization is the part worth carrying: joining a feed is procurement. Acting on one is incident response conducted on someone else's evidence.
Ranked by verification strength, evidence, and original report placement.
The engineer who leads the team running Dependabot at GitHub says the service monitors more than 30 million repositories for vulnerable and malicious dependencies as of 2026.
In 2026 GitHub extended malicious-package advisories from npm alone to eight package ecosystems by ingesting community intelligence from OpenSSF's malicious-packages repository.
GitHub had been flagging malware in npm since March, before the expansion to eight ecosystems.
Over the year ending May 2026, GitHub catalogued roughly 18 new malicious npm packages a day.
A malicious package cannot be remediated by upgrading the way an ordinary vulnerability can; the package is ripped out and every credential the build touched is rotated.
The mapping and validation layer ate most of GitHub's engineering cost for the integration and carries nearly all of the correctness risk.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Layered permissions, not just three GitHub tools, secure this dependency scanner1 distinct publisher
build
A hallucinated package name was already registered when the engineer went looking1 distinct publisher
build
Claude Code's new default is a confession: the approval prompt was never a control1 distinct publisher
build
One API call decides whether your SHA pin still means what it says1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One insider, nothing checkable
Everything load-carrying in this story — 30 million repositories, 18 malicious npm packages a day, the claim that mapping and validation ate most of the engineering budget — comes from one man writing about his own team, in Help Net Security's pages, with no dataset, no dashboard and no second party to compare against. The mechanics are specific enough to be credible and the author is the accountable engineer, which is why this does not score lower; but a reader who wanted to verify a single number here has nowhere to go.
Shipped, at a scale worth noting
This is not a proposal. The OpenSSF feed is wired into a service watching tens of millions of repositories, the advisory scope moved from npm to eight ecosystems this year, and the alerts go out unreviewed — deployment rather than pilot. What holds the number down is that we can see exactly one adopter of these practices, and the essay's claim that the same five lessons govern OSV and ISAC ingestion is asserted with no second integration to show for it.
Argues downward, not up
The rhetorical pressure runs the wrong way for hype: a vendor engineer with a 30-million-repository product uses his column to say the interesting part is the boring part, that the feed integration was cheap and the normalization layer expensive, and that every alert his system fires ends in a rip-out and a round of credential rotation. That is a deflationary posture, and it earns a modest negative. It is not further negative because the one claim doing the heaviest defensive work — the cap that supposedly bounds an unreviewed pipeline's worst day — is stated without a number.
The designer grading his own design
Read who benefits: a GitHub engineering lead, in a security trade publication, explaining why it is correct that his product ships malware advisories no human has read. The essay is generous to OpenSSF's commons, flattering to GitHub's engineering discipline, and structurally unable to report the one thing that would test either — how often those automatic advisories are wrong. None of that makes the account false; it does mean the flattering framing and the missing error rates come from the same pen.
Firm on shape, soft on figures
We would bet on the engineering picture — case-sensitivity mismatches, incompatible range semantics, self-echo through an aggregator, quarantine over silent repair are the kinds of details you only produce by having been bitten. We would not bet on the magnitudes, the cost split, or the sufficiency of the unquantified import cap, and with one publisher and one interested author there is no second reading available to raise that.