GitHub and PyPI Add Time-Based Supply Chain Defenses

GitHub and PyPI introduced time-based security delays in the Dependabot dependency management tool to combat supply chain attacks. The mechanism pauses before executing updates, narrowing the window for attackers to compromise packages.

7 reports · 5 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. https://ww

mastodon:infosec-exchangeother65d ago kagi ↗

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. https://www. bleepingcomputer.com/news/secu rity/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/

GitHub, PyPI add time-absed defenses against supply chain attacks https://www. bleepingcomputer.com/news/secu rity/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/?utm_source=dlvr.it&

mastodon:infosec-exchangeother65d ago wire ×2 kagi ↗

GitHub, PyPI add time-absed defenses against supply chain attacks https://www. bleepingcomputer.com/news/secu rity/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D

🤖 GitHub and PyPI add time-based defenses to Dependabot against supply chain attacks. The new mechanism introduces delays before executing dependency updates, limiting the window for attackers to com

mastodon:infosec-exchangeother65d ago kagi ↗

🤖 GitHub and PyPI add time-based defenses to Dependabot against supply chain attacks. The new mechanism introduces delays before executing dependency updates, limiting the window for attackers to compromise packages. 🔗 https://www. bleepingcomputer.com/news/secu rity/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/ # SupplyChain # Dependabot # CyberSec

🤖 GitHub and PyPI add time-based defenses against supply chain attacks: Dependabot introduces a security delay before activating detected dependencies, reducing the window for package compromise expl

mastodon:infosec-exchangeother64d ago kagi ↗

🤖 GitHub and PyPI add time-based defenses against supply chain attacks: Dependabot introduces a security delay before activating detected dependencies, reducing the window for package compromise exploitation. 🔗 https://www. bleepingcomputer.com/news/secu rity/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/ # SupplyChain # CyberSec # GitHub # PyPI