Update and Show Status of Dependabot Security Updates in API July 11, 2023 security-and-compliance You will now be able to see whether Dependabot security updates are enabled or disabled in the security and analysis block within the repository information you can fetch from the REST API, and enable or disable them via API requests.For more information, you can check out our repository API documentation. See more See more
Warn when the npm provenance source commit or repository cannot be found July 11, 2023 security npm will now check the linked source commit and repository when you view a package's provenance information on npmjs.com. If the linked source commit or repository cannot be found, an error displays at the top of the page and alongside the provenance information to let you know that provenance for this package can no longer be established. This can happen when a repository is deleted or made private.Note: In future releases, publishing a public package with provenance from a private source repository will not be allowed.Read more about publishing with provenance. See more See more