License data quality improvements
UpdateVerifiedAdded Sep 22, 2026
GitHub now uses package registries like npmjs.org and PyPI to determine license information for software components in the dependency graph. This improves the accuracy and completeness of the licenses shown in dependency insights, software bills of materials (SBOMs), the open source license compliance feature in GitHub Advanced Security, and the dependency...
Topics: Governance, Security
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Aug 18 | Credential revocation and deauthorization by token type Update | Update |
| Aug 19 | Track organization code quality trends GA | GA |
| Aug 7 | Secret scanning coverage updates Update | Update |
| Aug 20 | Code scanning adds a mitigated alert dismissal reason Update | Update |
| Aug 20 | Track GitHub Code Quality enablement changes in the audit log Update | Update |
| Aug 4 | Customize code scanning default setup at scale Update | Update |
| Aug 4 | Customize Dependabot pull request branch names Update | Update |
| Aug 4 | Code coverage automatic enablement in Code Quality settings Preview | Preview |