Skip to content
GitHub and PyPI add delays to slow supply

GitHub and PyPI add delays to slow supply

Feeds.4Sysops •IT News • July 26, 2026

GitHub and PyPI are adding time-based barriers that make it harder for malicious package releases to reach developers immediately or be inserted into trusted versions later. GitHub’s Dependabot, the service that opens pull requests for dependency updates, now waits 72 hours by default before proposing a newly published version. That pause gives security scanners and maintainers time to identify and remove compromised packages before automated updates spread them. Source

Extracted Entities

Attack Types (1)

Platforms (2)