Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    July 27, 2026

    Being a Luddite Is Fun Again

    July 27, 2026

    Infosec News Nuggets — July 27, 2026 – AboutDFIR

    July 27, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»GitHub, PyPI add time-absed defenses against supply chain attacks
    News

    GitHub, PyPI add time-absed defenses against supply chain attacks

    adminBy adminJuly 26, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    GitHub, PyPI add time-absed defenses against supply chain attacks

    GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.

    Specifically, Dependabot comes with a default three-day cooldown setting, while PyPI will reject new files uploaded to releases older than 14 days.

    The measure comes after the two development ecosystems experienced multiple high-profile attacks over the past year. Some notable examples include the ‘chalk’ and ‘debug’ attacks, the “s1ngularity” operation, the Shai-Hulud campaign, and the GhostAction supply-chain attack.

    image

    GitHub announced last month changes to tackle supply chain threats, and the hardening process progresses with the new measures.

    GitHub adds Dependabot cooldown

    Dependabot is GitHub’s dependency-update service that reads files containing information about new package versions and opens update pull requests to notify software maintainers.

    The tool now delays the package update process for 72 hours to reduce the risk of automatically adopting newly published malicious packages.

    In many recent cases, malicious npm packages were detected and flagged by security tools within minutes of being published.

    However, quick detection alone does not remove the threat, as repository maintainers and vendors must still take action to remove the packages, leaving a window during which developers and projects may download and incorporate the malicious code.

    While GitHub explained that the period of three days was chosen as a balanced point between avoiding risky releases while keeping up with the latest upgrades, it noted that users still have the option to configure a shorter or longer delay through Dependabot’s ‘cooldown’ configuration option.

    GitHub highlighted Dependabot’s cooldown limitations against longer-term compromise, recommending the use of lockfiles for dependency pinning, restricted-scope tokens, and disabling unnecessary installation scripts in CI.

    PyPI blocks release poisoning with 14-day cutoff

    PyPI announced that it now blocks maintainers from adding new files to a package release after 14 days have passed since its publication.

    The measure is intended to prevent attackers who compromise publishing tokens or workflows from poisoning old, trusted releases.

    The platform found that only a very small percentage of projects legitimately uploaded more than two weeks after publishing a release.

    It should be noted that no known past attacks on PyPI have been confirmed to use the said release poisoning technique that this new measure blocks, but the platform is acting preventatively in this case to block a dangerous possibility.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBlack Hat Intercepted | James Kettle, Director of Research at Portswicker
    Next Article Meta Logging Every Employee Keystroke | Threat Wire
    admin
    • Website

    Related Posts

    News

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    July 27, 2026
    News

    Being a Luddite Is Fun Again

    July 27, 2026
    News

    Infosec News Nuggets — July 27, 2026 – AboutDFIR

    July 27, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202638 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202638 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Our Picks

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    July 27, 2026

    Being a Luddite Is Fun Again

    July 27, 2026

    Infosec News Nuggets — July 27, 2026 – AboutDFIR

    July 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.