GitHub's Dependabot now waits 3 days before opening an update PR; PyPI locks old releases from new files. Both stop fast publish-and-yank package attacks. Neither stops a dormant backdoor. Watch your

GitHub's Dependabot now waits 3 days before opening an update PR; PyPI locks old releases from new files. Both stop fast publish-and-yank package attacks. Neither stops a dormant backdoor. Watch your build hosts. https:// suriq.io/blog/github-pypi-rele ase-cooldown-supply-chain-gap # SupplyChain # infosec # cybersecurity

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

GitHub's Dependabot now waits 3 days before opening an update PR; PyPI locks old releases from new files. Both stop fast publish-and-yank package attacks. Neither stops a dormant backdoor. Watch your

mastodon:infosec-exchangeother64d ago kagi ↗

GitHub's Dependabot now waits 3 days before opening an update PR; PyPI locks old releases from new files. Both stop fast publish-and-yank package attacks. Neither stops a dormant backdoor. Watch your build hosts. https:// suriq.io/blog/github-pypi-rele ase-cooldown-supply-chain-gap # SupplyChain # infosec # cybersecurity