GitHub's Dependabot now waits 3 days before opening an update PR; PyPI locks old releases from new files. Both stop fast publish-and-yank package attacks. Neither stops a dormant backdoor. Watch your
GitHub's Dependabot now waits 3 days before opening an update PR; PyPI locks old releases from new files. Both stop fast publish-and-yank package attacks. Neither stops a dormant backdoor. Watch your build hosts. https:// suriq.io/blog/github-pypi-rele ase-cooldown-supply-chain-gap # SupplyChain # infosec # cybersecurity