New GitHub, PyPI Policies Boost Supply Chain Security
GitHub and PyPI implement new policies to enhance supply chain security.
Summary
GitHub and PyPI have introduced new policies to bolster supply chain security. GitHub's Dependabot will now have a three-day cooldown period before opening pull requests for new releases, allowing time for security checks. PyPI is preventing the poisoning of older releases by blocking file uploads to releases older than 14 days, safeguarding against compromised publishing tokens.
Full text
GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases. To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a Dependabot cooldown, where the automation tool waits for at least three days after a release has been published before opening a pull request. “Waiting a few days before adopting a new release gives maintainers, security researchers, and automated scanners time to spot a malicious version and get it pulled before it ever reaches your pull requests,” GitHub explains. The three-day cooldown only applies to non-security version bumps, and the behavior can be modified through the configuration option in the dependabot.yml. “Three days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn’t hold your dependencies back longer than necessary,” GitHub notes. PyPI, on the other hand, is preventing the poisoning of releases older than 14 days by blocking the upload of new files to them.Advertisement. Scroll to continue reading. “This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised. As far as we are aware, this has not yet been abused, but there is no technical reason beyond that attackers weren’t aware it was possible,” PyPI says. The behavior will be enforced once ‘Upload 2.0 API’ and ‘Staged Previews’ have been standardized by PEP 694 and will affect only a small fraction of projects that still publish new files to older releases. Testing has shown that only 56 of the top 15,000 packages “had published a 3.14-compatible wheel more than 14 days after a release was available,” PyPI explains. According to the platform, the change should not only protect users but also eliminate cleanup work in the event of an attack, as it would be much easier to distinguish between compromised and non-compromised releases. Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack Related: Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire DentaQuest Data Breach Potentially Impacts Over 23 Million PeopleStrongestLayer Raises $4.1 Million in Seed Funding ExtensionEndpoint Security Firm Glow Launches With $180M in Funding at $1.2B ValuationEmpirical Security Raises $25 Million in Series A FundingNew HollowGraph Malware Abuses Microsoft 365 Calendar for C&C CommunicationEstée Lauder Discloses Impact From Oracle EBS Zero-Day HackClover Health Investments Discloses Data BreachZimbra Update Patches Critical Vulnerabilities Latest News PTC Windchill Vulnerability Exploited in Ransomware CampaignMedusaHVNC Malware Uses Hidden Windows Desktops to Evade DetectionNvidia and Tech Giants Launch AI Security AllianceCoca-Cola Confirms Data Breach After Fairlife Ransomware AttackBeelzebub Raises $3.4 Million for Hacker-Trapping PlatformWhat’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find OutHacked Public Wi-Fi Gateways Used to Harvest Corporate CredentialsAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveBarry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email