https://github.blog/2022-06-27-github-advisory-database-now-supports-erlang-and-elixir-packages/ / Blog * Engineering * Community * Product * Security * Open Source * Enterprise * Changelog * Education * Company Subscribe Search by Keyword [ ] Search * Company * Security GitHub Advisory Database now supports Erlang and Elixir packages! We're excited to announce that the GitHub Advisory Database now includes curated security advisories on Erlang, Elixir, and more. GitHub Advisory Database now supports Erlang and Elixir packages! Author Madison OliverMadison Oliver June 27, 2022 * * * GitHub is on a mission to create a more secure supply chain for all developers and organizations. To do that, we need to empower all developer communities with comprehensive vulnerability information and seamless remediation guidance. That's why we're excited to announce that the GitHub Advisory Database now includes curated security advisories for languages compiled to run on the BEAM virtual machine, including Elixir and Erlang. Elixir is a dynamic, functional language for building scalable and maintainable applications and is great at controlling vast amounts of infrastructure. Erlang is a general-purpose programming language and runtime environment that favors building scalable and concurrent systems. These languages, as well as others compiled to run on the BEAM virtual machine, are managed by the Hex package registry. The addition of the Erlang ecosystem expands our GitHub Advisory Database coverage to nine supported ecosystems: Composer (PHP), Go, Maven (Java), npm (JavaScript), NuGet (.NET), pip (Python), RubyGems (Ruby), Rust, and now Erlang (Hex). This new coverage ensures that any member of the Erlang and Elixir community can check for security issues in the same place that their code resides--on GitHub. Advisories GitHub believes that free and open security data is critical to empowering the industry as a whole to best secure our software supply chains. To support this mission, GitHub's Advisory Database is an open source database of security advisories focused on high-quality, actionable vulnerability information for developers. It's licensed under Creative Commons Attribution 4.0, so the data can be used anywhere and is forever free! Contributing to Erlang advisories We are also accepting community contributions on Hex packages now that the Advisory Database supports this ecosystem! Security researchers, academics, and enthusiasts can provide additional relevant information to further the community's understanding and awareness of these security advisories. Contributors can submit their edits following our community guidelines. Learn more Jump in, and explore Erlang advisories today, or learn more about our other supply chain security features as follows: * The GitHub Advisory Database * GitHub Security Advisories * Dependency graph * Dependabot alerts * Dependabot security updates Tags: * Security More on Security GitHub now publishes malware advisories in the GitHub Advisory Database GitHub now publishes malware advisories in the GitHub Advisory Database To combat the prevalence of malware in the open source ecosystem, GitHub now publishes malware occurrences in the GitHub Advisory Database. These advisories power Dependabot alerts and remain forever free and usable by the community. Brittany O'Shea & Kate Catlin Introducing Entitlements: GitHub's open source Identity and Access Management solution We're excited to announce that we're open sourcing our Identity and Access Management solution: Entitlements. Shawna Butterworth Eight years of the GitHub Security Bug Bounty program It was another record year for our Security Bug Bounty program. We're excited to highlight some achievements we've made together with the bounty community from 2021! Jill Mone-Corallo Related posts GitHub enables the development of functional safety applications by adding support for coding standards AUTOSAR C++ and CERT C++ Open Source GitHub enables the development of functional safety applications by adding support for coding standards AUTOSAR C++ and CERT C++ GitHub is excited to announce the release of CodeQL queries that implement the standards CERT C++ and AUTOSAR C++. These queries can aid developers looking to demonstrate ISO 26262 Part 6 process compliance. Brittany O'Shea Creating a more comprehensive dependency graph with build time detection Product Creating a more comprehensive dependency graph with build time detection Expand the completeness of your dependency graph by using the dependency submission API, which will create more comprehensive alerts on supply chain vulnerabilities Courtney Claessens The Android kernel mitigations obstacle race Security The Android kernel mitigations obstacle race In this post I'll exploit CVE-2022-22057, a use-after-free in the Qualcomm gpu kernel driver, to gain root and disable SELinux from the untrusted app sandbox on a Samsung Z flip 3. I'll look at various mitigations that are implemented on modern Android devices and how they affect the exploit. Man Yue Mo Explore more from GitHub Company Company The latest on GitHub, from GitHub. Learn more The ReadME Project The ReadME Project Stories and voices from the developer community. Learn more GitHub Actions GitHub Actions Native CI/CD alongside code hosted in GitHub. Learn more Work at GitHub! Work at GitHub! Check out our current job openings. Learn more Subscribe to The GitHub Insider A newsletter for developers covering techniques, technical guides, and the latest product innovations coming from GitHub. [ ] Subscribe Product * Features * Security * Enterprise * Customer Stories * Pricing * Resources Platform * Developer API * Partners * Atom * Electron * GitHub Desktop Support * Docs * Community Forum * Training * Status * Contact Company * About * Blog * Careers * Press * Shop * GitHub on Twitter * GitHub on Facebook * GitHub on YouTube * GitHub on Twitch * GitHub on TikTok * GitHub on LinkedIn * GitHub's organization on GitHub * (c) 2022 GitHub, Inc. * Terms * Privacy