
GitHub and PyPI Add Time-Based Defenses Against Supply Chain Attacks
GitHub and the Python Package Index (PyPI) have rolled out new time restrictions to combat a rising wave of software supply-chain attacks. GitHub’s Dependabot now features a three-day cooldown by default, while PyPI will block new file uploads to package releases older than 14 days. These security updates arrive after a turbulent year for both development platforms, marked by high-profile breaches such as the GhostAction and Shai-Hulud campaigns. By enforcing delays and rejecting late modifications to established code, the platforms aim to shrink the window hackers use to slip malware into trusted projects. Why it matters for Somali readers: For Somali developers and tech students relying on open-source packages, these updates provide an automated layer of security. It reduces the risk of accidentally downloading malicious code when building local startups or learning to program.
Read our sourcing and corrections policy
Related News
Comments
Be the first to comment on this story!


