GitHub targets vulnerable open source components

GitHub targets vulnerable open source components