//pragmatic leaders

signal

GitHub and PyPI slowed Dependabot and locked old releases to curb supply chain attacks

Slowing automated dependency updates and locking old releases raises the attacker's cost and reduces the risk of widespread supply chain compromise by making it easier to isolate and remediate poisoned packages.

Frame 1 of 4

GitHub and PyPI introduce cooldown and release locking policies

GitHub added a three-day cooldown for Dependabot before it opens pull requests on new releases. PyPI now rejects file uploads to releases older than 14 days. These changes aim to prevent fast propagation of malicious code and poisoning of stable releases.