← Back

Wire · technology

GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks

Published

27 July 2026

Topic

technology

Sectors

Cybersecurity

Geography

United States

Source

Read at devops.com

Verified

Fusion42 · 27 July 2026 · Fusion42 review

GitHub's Dependabot now delays routine version updates by three days by default; PyPI blocks new files from being added to releases older than 14 days. Both changes aim to slow automated adoption and give security scanners and maintainers time to detect and respond to malicious package releases before they propagate into production systems.

This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

If you ship code that auto-updates dependencies, your systems now have built-in delays that work whether you want them or not. Use that window to lock your builds to specific versions and tighten token permissions, or accept that your deployments will lag behind open-source releases by default.

Related on Wire

Topics

Cybersecuritydependency-managementpackage-registry-securitysupply-chain-defenceautomation-riskopen-source-security