www.securityweek.com 7/27/2026, 2:41:23 PM · external

GitHub and PyPI add delays to thwart supply chain attacks

GitHub and PyPI add delays to thwart supply chain attacks
CyberSIXT Evidence Panel
Primary Source github.blog

GITHUB and PyPI have implemented new policies to enhance supply chain security against malicious code. GitHub's Dependabot will now wait three days to open pull requests for non-security version updates, allowing time for detection of malicious versions. Meanwhile, PyPI has introduced a restriction that blocks updates to releases older than 14 days, aimed at preventing the poisoning of established versions. These changes are designed to mitigate the risk from supply chain attacks and allow easier identification of compromised releases.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline