bleeping-computer · Crawled Jul 26, 2026

GitHub, PyPI add time-absed defenses against supply chain attacks

Read original article ↗

AI Summary

GitHub and PyPI have implemented new time-based defenses to mitigate supply chain attacks. GitHub's Dependabot now enforces a default 72-hour cooldown period before updating dependencies, reducing the risk of automatic adoption of malicious packages. PyPI has introduced a 14-day cutoff, blocking the addition of new files to older package releases to prevent release poisoning. These measures aim to limit the impact of compromised tokens or malicious actors in the software supply chain.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.