Wire · technology
GitHub delays version updates so malware gets caught first
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 27 July 2026 · Fusion42 review
GitHub's Dependabot now delays non-security version updates by three days before opening pull requests, preventing automatic integration of newly published malware during the typical two-hour window before detection. The change follows a September 2025 incident where poisoned npm packages (chalk, debug) reached 2 billion weekly downloads before removal.
This Wire brief sits within Fusion42's coverage of Enterprise Software, Cybersecurity and Data Infrastructure. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ ◆ The Wire takeaway
Your dependency automation now stops for three days to let malware get caught first. If you've configured Dependabot to auto-merge, you need to review that policy this week—the tool is no longer your speed advantage, it's your safety net.
◆ Related on Wire
◆ Topics