GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates
ID: 6d508ad2-0d08-5d62-8484-300e495bbf4a
STIX ID: report--6d508ad2-0d08-5d62-8484-300e495bbf4a
Feed Name: cybersecurityNews.com
GitHub is adding a default three-day cooldown to Dependabot version updates after incidents where attackers phished npm maintainers and published trojanized package releases (e.g., chalk, debug) that could redirect cryptocurrency payments; automated dependency tools previously created pull requests from those malicious releases before they were detected and removed. The change delays non-security version updates to give maintainers, researchers, and scanners time to detect and remove malicious releases, while keeping security updates immediate; the report notes a large and growing volume of npm malware advisories (about 6,500 in the year ending May 2026) and stresses that cooldowns are a mitigation, not a complete solution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
