- What: GitHub and PyPI implement new security measures against supply-chain attacks
- Impact: Developers and package maintainers may need to adjust their workflows to accommodate new cooldown and upload policies
Application security , Third-party code GitHub and PyPI implement new security measures against supply-chain attacks July 27, 2026 Share By SC Staff (Credit: Robert – stock.adobe.com) Based on information from Bleeping Computer, GitHub and the Python Package Index (PyPI) have introduced new time-based security mechanisms within their development tools to combat supply-chain attacks and mitigate their potential impact. GitHub's Dependabot, a tool that automates dependency updates, now includes a default three-day cooldown period. This delay is intended to prevent the automatic adoption of newly published malicious packages, as attackers have previously exploited the window between a malicious package's publication and its removal. While this period can be configured, it aims to balance security with the need for timely updates. Concurrently, PyPI has implemented a policy rejecting new files uploaded to package releases older than 14 days. This measure is designed to prevent attackers who gain access to publishing tokens or workflows from compromising older, trusted releases. Although no confirmed attacks on PyPI have utilized this specific release poisoning technique, the platform is proactively blocking this potential threat vector. These changes follow a series of high-profile supply-chain attacks impacting both ecosystems over the past year, including incidents involving popular packages like 'chalk' and 'debug'. Source: Bleeping Computer SC Staff Related Application security Malvertising campaign assembles malware in browser SC Staff July 27, 2026 A large-scale malvertising campaign is using fake websites for Solana, Luno, and TradingView, employing malicious JavaScript to assemble malware directly in the user's browser. AI/ML AI plans are being approved. Recovery plans are not Paul Wagenseil July 27, 2026 Do you spend more time managing AI agents than you save by using them? Here's how to make your ROI on agentic deployment. AI/ML Balancing lead generation, growth, and security in the age of AI search Solomon Adote July 27, 2026 AI search visibility demands smarter bot security, not open access. Related Events Cybercast Bridging the Gap from CISO-Developed Tools to Black Hat Hype: What AI Security Leaders Should Watch Next On-Demand Event Cybercast Protecting Application User Data for Better Privacy, Governance, and Compliance On-Demand Event Cybercast The Next Evolution of Application Security: AI- Accelerated DevSecOps On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Banner Browser Cache Cramming Common Gateway Interface (CGI) Client Cookie DLL Injection Dynamic Link Library You can skip this ad in 5 seconds