Skip to main content

Tag: dependabot

2 articles

Software development workspace with laptop, notebook, and papers on a desk in front of a blurred coding environment and a…

GitHub Targets Supply Chain Attacks with Dependabot Cooldown

GitHub's new Dependabot cooldown feature gives you a security boost by waiting at least three days after a release is published before updating dependencies, helping to prevent rapid adoption of malicious package releases. This brief pause allows time to catch poisoned or trojanized packages, keeping your projects safer.

Analyst 207
Developer workstation with laptop and notes in a bright, daytime office environment.

GitHub, PyPI Fortify Defenses Against Supply Chain Attacks

GitHub and PyPI are stepping up their game to shield against supply chain attacks, introducing time-based gates to slow down the release of potentially risky package updates. GitHub's Dependabot now delays updates for 72 hours, while PyPI will reject new files added to releases over 14 days old.

Analyst 207