GitHub and PyPI Add Time-Based Supply Chain Defenses
GitHub and PyPI introduced time-based security delays in the Dependabot dependency management tool to combat supply chain attacks. The mechanism pauses before executing updates, narrowing the window for attackers to compromise packages.