GitHub Dependabot and PyPI add time-based supply-chain defenses
Security Tool/Service
Updated: 26.07.2026 17:13
· First: 26.07.2026 17:13
· 📰 1 src / 1 articles
· H score: 11
GitHub Dependabot and PyPI added time-based controls that slow malicious package adoption and restrict late release tampering across the software supply chain. Dependabot now defaults to a 72-hour cooldown, while PyPI rejects new files for releases older than 14 days. The changes are meant to reduce exposure to newly published malicious packages and release poisoning. The rollout tightens package trust windows after a run of supply-chain attacks across both ecosystems.