Wire · technology
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 27 July 2026 · Fusion42 review
GitHub's Dependabot now delays routine version updates by three days by default; PyPI blocks new files from being added to releases older than 14 days. Both changes aim to slow automated adoption and give security scanners and maintainers time to detect and respond to malicious package releases before they propagate into production systems.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ ◆ The Wire takeaway
If you ship code that auto-updates dependencies, your systems now have built-in delays that work whether you want them or not. Use that window to lock your builds to specific versions and tighten token permissions, or accept that your deployments will lag behind open-source releases by default.
◆ Related on Wire
◆ Topics