{"id":4660,"date":"2026-07-27T10:16:58","date_gmt":"2026-07-27T10:16:58","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/07\/27\/github-and-pypi-bet-on-time-to-slow-down-software-supply-chain-attacks\/"},"modified":"2026-07-27T10:16:58","modified_gmt":"2026-07-27T10:16:58","slug":"github-and-pypi-bet-on-time-to-slow-down-software-supply-chain-attacks","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/07\/27\/github-and-pypi-bet-on-time-to-slow-down-software-supply-chain-attacks\/","title":{"rendered":"GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks"},"content":{"rendered":"<div><img data-opt-id=155908503  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/07\/github_pypi_supply_chain_770x330.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=1616390765  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/07\/github_pypi_supply_chain_770x330-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p><span>GitHub and the Python Package Index (PyPI) just added a new layer of defense against supply chain attacks, and it doesn\u2019t involve scanning code or blocking uploads outright. It involves waiting.<\/span><\/p>\n<p><span>GitHub\u2019s Dependabot now applies a default three-day cooldown before opening a pull request for a routine version update. PyPI, meanwhile, will no longer accept new files uploaded to a release once it\u2019s more than 14 days old. Neither change stops a bad actor from publishing malicious code in the first place. Both are designed to shrink the window during which that code can quietly work its way into production systems before anyone notices.<\/span><\/p>\n<p><span>The reasoning behind both moves is simple. A newly published package version often gets pulled into build pipelines within minutes of going live, well before a person or a scanner has had time to review it. Security tools are usually fast at flagging something suspicious. But flagging isn\u2019t the same as fixing. A maintainer still has to pull the bad version, and until that happens, anyone updating on the old schedule is exposed. A cooldown period buys back some of that lost time. By holding off a few days before adopting a new release, GitHub gives maintainers, researchers, and automated scanners a chance to catch a malicious version and get it removed before it ever lands in a pull request.<\/span><\/p>\n<p><span>GitHub settled on three days as its default after weighing two competing pressures: keeping teams current on their dependencies without exposing them to releases that haven\u2019t had time to be vetted. Teams that want a shorter or longer delay can still configure it themselves through Dependabot\u2019s cooldown settings \u2014 the default just changes what happens for everyone who doesn\u2019t.<\/span><\/p>\n<p><span>PyPI\u2019s change addresses a related but different risk. Instead of guarding against a brand-new malicious package, it closes off a path attackers could use to poison a release that\u2019s already been trusted and in use for weeks. Once a release passes the 14-day mark, PyPI simply won\u2019t accept new files added to it. That protects against a scenario where an attacker gains access to a compromised publishing token or workflow and quietly slips malicious code into an old, stable release rather than pushing something new and conspicuous. PyPI has said it isn\u2019t aware of this technique being used in a real attack yet \u2014 the restriction is preventative, closing a door before anyone tries to walk through it.<\/span><\/p>\n<p><span>The data behind that decision is worth noting. When the PyPI team checked how often projects legitimately publish new files to old releases, the number was small even in edge cases: only a tiny fraction of the platform\u2019s most popular packages had added a Python 3.14-compatible build more than two weeks after the original release went out. That gave the Python Software Foundation enough confidence that the restriction wouldn\u2019t disrupt normal workflows for most maintainers.<\/span><\/p>\n<p><span>Neither change happened in isolation. Both platforms have spent the past year responding to a steady run of high-profile incidents \u2014 compromises tied to widely used npm packages, the s1ngularity campaign, the Shai-Hulud worm, and the GhostAction attack against PyPI publishing credentials. GitHub had already announced changes to npm security last month, and this cooldown builds directly on that effort.<\/span><\/p>\n<p><span>\u201cElapsed time now governs when an automated update reaches a pull request and how long a published release stays open to new files,\u201d said Mitch Ashley, VP and practice lead, software lifecycle engineering and AI-native software engineering at <a href=\"https:\/\/futurumgroup.com\/\" target=\"_blank\" rel=\"noopener\">The Futurum Group<\/a>.<\/span><\/p>\n<p><span>None of this replaces the fundamentals, and GitHub has been upfront about that. A cooldown does little against an attack that plays out over months rather than days \u2014 the kind where an attacker spends time earning a maintainer\u2019s trust before slipping in something harmful. GitHub still recommends pairing the cooldown with lockfiles for dependency pinning, tightly scoped access tokens, and turning off installation scripts that aren\u2019t strictly needed in CI pipelines. Time helps. It isn\u2019t a substitute for judgment.<\/span><\/p>\n<p><span>Ashley pointed out that the cooldown doesn\u2019t apply evenly across the board. \u201cDependabot\u2019s cooldown covers version updates only,\u201d he said. \u201cSecurity updates still open immediately, which leaves the fastest automated path into a build pipeline unchanged. Teams running unattended merges should confirm which path the new default actually closed.\u201d<\/span><\/p>\n<p><span>For DevOps and platform engineering teams, the specific numbers matter less than the shift in posture they represent. Package registries have long optimized for speed \u2014 get the latest release out, get it adopted, move on. These changes are a quiet admission that speed itself has become part of the attack surface. Teams that rely heavily on automated dependency bots without a human review step now get a small, built-in buffer by default. Teams that already pin dependencies to commit hashes or run their own internal package mirrors had some version of this protection already; now it\u2019s becoming a platform-level default for everyone else.<\/span><\/p>\n<p><span>It\u2019s a modest change with an outsized rationale. In software supply chain security, the first few days after a release ships are often the most dangerous. Giving that window a little more room to close may be one of the simplest, cheapest defenses available right now.<\/span><\/p>\n<p><a href=\"https:\/\/devops.com\/github-and-pypi-bet-on-time-to-slow-down-software-supply-chain-attacks\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>GitHub and the Python Package Index (PyPI) just added a new layer of defense against supply chain attacks, and it [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4661,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-4660","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4660"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4660\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/4661"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}