← Back

Wire · technology

GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks

Published

27 July 2026

Topic

technology

Sectors

Cybersecurity

Geography

United States

Source

Read at devops.com

Verified

Fusion42 · 27 July 2026 · Fusion42 review

GitHub's Dependabot now delays routine version updates by three days by default; PyPI blocks new files from being added to releases older than 14 days. Both changes aim to slow automated adoption and give security scanners and maintainers time to detect and respond to malicious package releases before they propagate into production systems.

This Wire brief sits within Fusion42's coverage of Cybersecurity, and 7 sources have reported it between 27 Jul 2026 and 31 Jul 2026.

◆ The Wire takeaway

If you ship code that auto-updates dependencies, your systems now have built-in delays that work whether you want them or not. Use that window to lock your builds to specific versions and tighten token permissions, or accept that your deployments will lag behind open-source releases by default.

Coverage

7 sources · first reported 27 Jul 2026 · latest 31 Jul 2026

Related on Wire

Topics

Cybersecuritydependency-managementpackage-registry-securitysupply-chain-defenceautomation-riskopen-source-security