Official company update
Dependency Firewall: Block risky packages before the build
GitLab·about.gitlab.com·
What the source says
Attackers disguise malicious packages as ones you trust. In June 2026, GitLab researchers found five malicious PyPI packages , four of them typosquats of Flask, Requests, and NumPy, that run at install time and steal CI/CD credentials. Additionally, AI coding agents now add open source dependencies on their own, often unreviewed, so developers don't have ove
Checking access…
The original publication, including any images and updates, remains with the publisher.
Checking free source access…
More about GitLab
Official · about.gitlab.comTrack organization-wide security risk in one dashboardOfficial · about.gitlab.comEvery artifact your teams ship, assembled right the first timeOfficial · about.gitlab.comGitLab Transcend: Speed you can trust, all the way to productionOfficial · about.gitlab.comTwo front doors: Module-level access in a Django GRC app