If I understand correctly, you currently only review advisories about Composer packages from https://packagist.org/. Are there plans to add support for other well known Composer repositories like [https://packages.drupal.org/](https://www.drupal.org/docs/develop/using-composer/using-packagesdrupalorg) or https://wpackagist.org? This could allow warning GitHub projects using vulnerable versions of packages from these repositories.