# How we took malware advisories beyond npm

> Quelle: GitHub Blog — https://github.blog/security/supply-chain-security/how-we-took-malware-advisories-beyond-npm/

## Maßnahmen

- [ ] Betroffenheit im eigenen Stack prüfen: Versionen/Komponenten abgleichen.
- [ ] Originalquelle / Hersteller-Advisory lesen: https://github.blog/security/supply-chain-security/how-we-took-malware-advisories-beyond-npm/
- [ ] Verfügbaren Patch oder Workaround einspielen und dokumentieren.
