GITHUB and PyPI have implemented new policies to enhance supply chain security against malicious code. GitHub's Dependabot will now wait three days to open pull requests for non-security version updates, allowing time for detection of malicious versions. Meanwhile, PyPI has introduced a restriction that blocks updates to releases older than 14 days, aimed at preventing the poisoning of established versions. These changes are designed to mitigate the risk from supply chain attacks and allow easier identification of compromised releases.
GitHub and PyPI add delays to thwart supply chain attacks
CyberSIXT Evidence Panel
Primary Source
github.blog
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
GitHub and PyPI add delays to thwart supply chain attacks
www.securityweek.com
-
GitHub introduces 3 day Dependabot cooldown to stop risky updates
thehackernews.com