ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
GitHub's Dependabot now flags malware across eight package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer, by importing OpenSSF's malicious-packages data. The pipeline auto-publishes advisories, skips round-trip reports, and includes batch caps, provenance, and rollback protections.
Tap to vote and see what everyone thinks.
Summary by ByteBrief