logo

New GitHub, PyPI Policies Boost Supply Chain Security

ID: f52ac1bf-4cdb-5b1f-9f77-18226a1e5d53

STIX ID: report--f52ac1bf-4cdb-5b1f-9f77-18226a1e5d53

Feed Name: CosmicBytez Labs

Date Published: 2026-07-27

Date Updated: 2026-07-28

...
...

Two major open-source distribution platforms announced targeted policy changes to reduce supply-chain poisoning: GitHub will add a configurable three-day cooldown before Dependabot opens PRs for non-security package updates, and PyPI will block uploads to releases older than 14 days to prevent retroactive file poisoning. These incremental hardening steps are intended to reduce the window attackers exploit when publishing malicious package versions or adding files to long-stable releases, and require minimal action from most consumers while maintainers who upload to old releases may need to adjust workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.