Wire · technology
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 27 July 2026 · Fusion42 review
GitHub's Dependabot now delays routine version updates by three days by default; PyPI blocks new files from being added to releases older than 14 days. Both changes aim to slow automated adoption and give security scanners and maintainers time to detect and respond to malicious package releases before they propagate into production systems.
This Wire brief sits within Fusion42's coverage of Cybersecurity, and 7 sources have reported it between 27 Jul 2026 and 31 Jul 2026.
◆ ◆ The Wire takeaway
If you ship code that auto-updates dependencies, your systems now have built-in delays that work whether you want them or not. Use that window to lock your builds to specific versions and tighten token permissions, or accept that your deployments will lag behind open-source releases by default.
◆ Coverage
7 sources · first reported 27 Jul 2026 · latest 31 Jul 2026
◆ Related on Wire
◆ Topics