Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Anduril reportedly in talks to raise funding at $100B valuation, more than 3x last year’s mark

    July 26, 2026

    Mira Murati’s Inkling AI Model Review: Best Open-Source Model in the West

    July 26, 2026

    Would you pay $58.5m to live New York City’s historic Flatiron Building?

    July 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Anduril reportedly in talks to raise funding at $100B valuation, more than 3x last year’s mark
    • Mira Murati’s Inkling AI Model Review: Best Open-Source Model in the West
    • Would you pay $58.5m to live New York City’s historic Flatiron Building?
    • Trump Seems Trapped by Iran War, Even as He Wields the World’s Biggest Hammer
    • How China exploits EU divisions over trade
    • US accuses American of allegedly wiping his phone using a ‘duress’ password during border search
    • GitHub, PyPI add time-absed defenses against supply chain attacks
    • Multi-trillion-dollar offshore engine driving 90% of crypto trading arrives in America
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, July 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    GitHub, PyPI add time-absed defenses against supply chain attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 26, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.

    Specifically, Dependabot comes with a default three-day cooldown setting, while PyPI will reject new files uploaded to releases older than 14 days.

    The measure comes after the two development ecosystems experienced multiple high-profile attacks over the past year. Some notable examples include the ‘chalk’ and ‘debug’ attacks, the “s1ngularity” operation, the Shai-Hulud campaign, and the GhostAction supply-chain attack.

    image

    GitHub announced last month changes to tackle supply chain threats, and the hardening process progresses with the new measures.

    GitHub adds Dependabot cooldown

    Dependabot is GitHub’s dependency-update service that reads files containing information about new package versions and opens update pull requests to notify software maintainers.

    The tool now delays the package update process for 72 hours to reduce the risk of automatically adopting newly published malicious packages.

    In many recent cases, malicious npm packages were detected and flagged by security tools within minutes of being published.

    However, quick detection alone does not remove the threat, as repository maintainers and vendors must still take action to remove the packages, leaving a window during which developers and projects may download and incorporate the malicious code.

    While GitHub explained that the period of three days was chosen as a balanced point between avoiding risky releases while keeping up with the latest upgrades, it noted that users still have the option to configure a shorter or longer delay through Dependabot’s ‘cooldown’ configuration option.

    GitHub highlighted Dependabot’s cooldown limitations against longer-term compromise, recommending the use of lockfiles for dependency pinning, restricted-scope tokens, and disabling unnecessary installation scripts in CI.

    PyPI blocks release poisoning with 14-day cutoff

    PyPI announced that it now blocks maintainers from adding new files to a package release after 14 days have passed since its publication.

    The measure is intended to prevent attackers who compromise publishing tokens or workflows from poisoning old, trusted releases.

    The platform found that only a very small percentage of projects legitimately uploaded more than two weeks after publishing a release.

    It should be noted that no known past attacks on PyPI have been confirmed to use the said release poisoning technique that this new measure blocks, but the platform is acting preventatively in this case to block a dangerous possibility.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Add attacks chain defenses GitHub PyPI supply timeabsed
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    India Orders GitHub to Take Down Jack Dorsey’s Bitchat Amid Protests

    Binance Runs Phishing Attacks on Staff to Fight Social Engineering

    Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

    Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Anduril reportedly in talks to raise funding at $100B valuation, more than 3x last year’s mark

    July 26, 2026

    Mira Murati’s Inkling AI Model Review: Best Open-Source Model in the West

    July 26, 2026

    Would you pay $58.5m to live New York City’s historic Flatiron Building?

    July 26, 2026

    Trump Seems Trapped by Iran War, Even as He Wields the World’s Biggest Hammer

    July 26, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Anduril reportedly in talks to raise funding at $100B valuation, more than 3x last year’s mark

    July 26, 2026

    Mira Murati’s Inkling AI Model Review: Best Open-Source Model in the West

    July 26, 2026

    Would you pay $58.5m to live New York City’s historic Flatiron Building?

    July 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.