GitHub disclosed security measures to prevent supply chain attacks on npm packages and GitHub Actions. The initiative targets protecting open source dependencies and CI/CD workflows from compromise.
GitHub and PyPI introduced time-based security delays in the Dependabot dependency management tool to combat supply chain attacks. The mechanism pauses before executing updates, narrowing the window for attackers to compromise packages.