Official company update

Dependency Firewall: Block risky packages before the build

GitLab·about.gitlab.com·

What the source says

Attackers disguise malicious packages as ones you trust. In June 2026, GitLab researchers found five malicious PyPI packages , four of them typosquats of Flask, Requests, and NumPy, that run at install time and steal CI/CD credentials. Additionally, AI coding agents now add open source dependencies on their own, often unreviewed, so developers don't have ove

Checking access…

The original publication, including any images and updates, remains with the publisher.

Checking free source access…

More about GitLab