⌁ DAY 65

GitHub and PyPI Add Time-Based Supply Chain Defenses

2 beadsJul 26 → Jul 29moved 62d ago

The wire

2026-07-29

GitHub announces supply chain attack prevention measures

broke 62d ago · 4 reports · other · tech

GitHub disclosed security measures to prevent supply chain attacks on npm packages and GitHub Actions. The initiative targets protecting open source dependencies and CI/CD workflows from compromise.

2026-07-26

GitHub and PyPI Add Time-Based Supply Chain Defenses

broke 65d ago · 7 reports · other · tech

GitHub and PyPI introduced time-based security delays in the Dependabot dependency management tool to combat supply chain attacks. The mechanism pauses before executing updates, narrowing the window for attackers to compromise packages.