Skip to content

License data quality improvements

UpdateVerifiedAdded Sep 22, 2026

GitHub now uses package registries like npmjs.org and PyPI to determine license information for software components in the dependency graph. This improves the accuracy and completeness of the licenses shown in dependency insights, software bills of materials (SBOMs), the open source license compliance feature in GitHub Advanced Security, and the dependency...

Topics: Governance, Security

GitHub's release notes

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

Every GitHub Advanced Security release

Also shipped on Aug 13, 2026

GitHub in August 2026

Weekly: the week's data and AI releases, Tuesday mornings.