Dependabot now detects malware in npm dependencies - GitHub Changelog
Back to changelog You can now receive Dependabot alerts when your repositories depend on npm packages with known malicious versions. When you enable malware alerting, Dependabot matches your npm dependencies against malware…