GitHub, PyPI add time-absed defenses against supply chain attacks
5 Articles
5 Articles
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]
New GitHub, PyPI Policies Boost Supply Chain Security
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek.
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
GitHub and the Python Package Index (PyPI) just added a new layer of defense against supply chain attacks, and it doesn’t involve scanning code or blocking uploads outright. It involves waiting. GitHub’s Dependabot now applies a default three-day cooldown before opening a pull request for a routine version update. PyPI, meanwhile, will no longer accept new files uploaded to a release once it’s more than 14 days old. Neither change stops a bad ac…
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project," the Microsoft-owned subsidiary said. According to GitHub, the
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium



