Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

GitHub, PyPI add time-absed defenses against supply chain attacks

0
Medium
Vulnerabilitypython
Published: 07/26/2026 (07/26/2026, 14:13:39 UTC)
Source: Bleeping Computer

Description

GitHub and PyPI have introduced time-based defenses in their dependency management and package publishing processes to mitigate supply chain attacks. GitHub's Dependabot now enforces a default 72-hour cooldown before automatically updating dependencies, reducing the risk of quickly adopting malicious packages. PyPI blocks maintainers from adding new files to package releases older than 14 days to prevent release poisoning. These measures respond to recent high-profile supply chain attacks and aim to limit the impact of compromised packages or publishing tokens.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/26/2026, 14:37:15 UTC

Technical Analysis

GitHub and PyPI implemented time-based mitigation mechanisms to reduce supply chain attack risks. Dependabot, GitHub's dependency update tool, enforces a default three-day cooldown before applying package updates, allowing time to detect malicious packages before automatic adoption. This cooldown is configurable by users. PyPI now rejects new file uploads to releases older than 14 days, preventing attackers from poisoning trusted older releases by compromising publishing credentials. These changes follow multiple supply chain attacks in the past year and are part of ongoing efforts to harden package ecosystems.

Potential Impact

These defenses reduce the risk of automatically incorporating malicious or poisoned packages by introducing delays and restricting modifications to older releases. While no known attacks have exploited PyPI's release poisoning technique, the measures proactively block this potential threat. The cooldown in Dependabot limits rapid propagation of malicious packages, but does not eliminate longer-term compromise risks. Overall, these mitigations help limit the window of exposure to supply chain attacks in Python package ecosystems.

Mitigation Recommendations

The time-based defenses are already implemented by GitHub and PyPI. Users should configure Dependabot cooldown settings according to their risk tolerance. GitHub recommends additional mitigations such as using lockfiles for dependency pinning, restricting token scopes, and disabling unnecessary installation scripts in CI environments. No further immediate action is required to address these specific threats beyond adopting these recommended best practices.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/","fetched":true,"fetchedAt":"2026-07-26T14:37:08.191Z","wordCount":692}

Threat ID: 6a661b949c2644c7f8e1b3db

Added to database: 07/26/2026, 14:37:08 UTC

Last enriched: 07/26/2026, 14:37:15 UTC

Last updated: 07/26/2026, 15:18:54 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses