GitHub and PyPI are adding time-based barriers that make it harder for malicious package releases to reach developers immediately or be inserted into trusted versions later. GitHub’s Dependabot, the service that opens pull requests for dependency updates, now waits 72 hours by default before proposing a newly published version. That pause gives security scanners and maintainers time to identify and remove compromised packages before automated updates spread them. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
