GitHub and PyPI Implement Time-Based Measures Against Supply Chain Attacks

GitHub and PyPI Implement Time-Based Measures Against Supply Chain Attacks

First seen 26 Jul 2026, 18:04 UTC BleepingcomputerFeeds.4Sysopswww.tines.com 87% similarity 51.9

Article Content

Browse articles
ThreatCluster

GitHub and PyPI have introduced time-based defenses to mitigate supply chain attacks. GitHub's Dependabot now includes a default three-day cooldown before proposing updates, allowing time for security checks. PyPI has implemented a policy that blocks uploads of new files to a package release older than 14 days. These measures follow multiple high-profile attacks, including the 'chalk' and 'debug' attacks, and aim to prevent the incorporation of malicious packages into trusted releases. The changes are part of a broader effort to enhance security in development ecosystems. GitHub recommends additional practices like using lockfiles and restricted-scope tokens for better security. The updates are preventative, as no confirmed attacks exploiting these specific vulnerabilities have been reported on PyPI.

Key Points: • GitHub's Dependabot now has a default three-day cooldown for package updates. • PyPI blocks new file uploads to releases older than 14 days to prevent compromise. • These measures are a response to recent high-profile supply chain attacks.

ThreatCluster AI

Timeline

2026-07-26
GitHub and PyPI announce new security measures
Both platforms introduced time-based barriers to slow down the release of potentially malicious packages.
BleepingComputer
2026-07-26
Dependabot cooldown feature implemented
Dependabot now waits 72 hours before proposing updates to allow for security checks.
Feeds.4Sysops
2026-07-26
PyPI restricts file uploads
PyPI now prevents uploads of new files to releases older than 14 days to block potential release poisoning.
BleepingComputer

Community

Browse all →