GitHub added a 3-day Dependabot cooldown; PyPI now blocks new files on releases older than 14 days. Measures limit impact of malicious packages after recent high-profile supply-chain attacks. https://
GitHub added a 3-day Dependabot cooldown; PyPI now blocks new files on releases older than 14 days. Measures limit impact of malicious packages after recent high-profile supply-chain attacks. https:// threatintel.cc/2026/07/27/gith ub-pypi-add-timebased-defenses.html