Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Threads users can now chat with Meta AI in their DMs

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Threads users can now chat with Meta AI in their DMs
    • Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents
    • Nvidia and Tech Giants Launch AI Security Alliance
    • Tether’s XAUT Gains Shariah Certification for Islamic Finance
    • NASA’s Swift Sees ‘Wandering’ Mega Black Hole Shredding Star
    • Serica Energy wins race for Pharos Energy with €170 million takeover agreement
    • New Trump Rule Could Exclude U.S. Scientists From Critical Discoveries — ProPublica
    • India’s ‘Cockroach’ Protesters Disperse, But Questions Remain on Education and Dissent
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, July 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New GitHub, PyPI Policies Boost Supply Chain Security

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 27, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases.

    To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a Dependabot cooldown, where the automation tool waits for at least three days after a release has been published before opening a pull request.

    “Waiting a few days before adopting a new release gives maintainers, security researchers, and automated scanners time to spot a malicious version and get it pulled before it ever reaches your pull requests,” GitHub explains.

    The three-day cooldown only applies to non-security version bumps, and the behavior can be modified through the configuration option in the dependabot.yml.

    “Three days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn’t hold your dependencies back longer than necessary,” GitHub notes.

    PyPI, on the other hand, is preventing the poisoning of releases older than 14 days by blocking the upload of new files to them.

    Advertisement. Scroll to continue reading.

    “This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised. As far as we are aware, this has not yet been abused, but there is no technical reason beyond that attackers weren’t aware it was possible,” PyPI says.

    The behavior will be enforced once ‘Upload 2.0 API’ and ‘Staged Previews’ have been standardized by PEP 694 and will affect only a small fraction of projects that still publish new files to older releases.

    Testing has shown that only 56 of the top 15,000 packages “had published a 3.14-compatible wheel more than 14 days after a release was available,” PyPI explains.

    According to the platform, the change should not only protect users but also eliminate cleanup work in the event of an attack, as it would be much easier to distinguish between compromised and non-compromised releases.

    Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack

    Related: Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

    Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks

    Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack

    Boost chain GitHub policies PyPI Security supply
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Nvidia and Tech Giants Launch AI Security Alliance

    PTC Windchill Vulnerability Exploited in Ransomware Campaign

    Bitmine Nears Goal of Controlling 5% of Ethereum Supply With $11.8 Billion Treasury

    Shadow AI agents are multiplying. Here’s how to find and secure them.

    MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

    Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Threads users can now chat with Meta AI in their DMs

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026

    Tether’s XAUT Gains Shariah Certification for Islamic Finance

    July 27, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Threads users can now chat with Meta AI in their DMs

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.