Git your patches here! GitHub offers to brew automatic pull requests loaded with vuln fixes

Your repo’s dependencies need updating to close a hole? We’re way ahead of you, pal GitHub can now automagically offer security patches for projects’ third-party dependencies.… The Register – Security

Someone slipped a vuln into crypto-wallets via an NPM package. Then someone else siphoned off $13m in coins to protect it from thieves

What a wild ride, eh Komodo? Blockchain biz Komodo this week said it had used a vulnerability discovered by JavaScript package biz NPM to take control of some older Agama cryptocurrency wallets to prevent hackers from doing the same.… The Register – Security