Wire · technology
GitHub delays version updates so malware gets caught first
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 27 July 2026 · Fusion42 review
GitHub's Dependabot now delays non-security version updates by three days before opening pull requests, preventing automatic integration of newly published malware during the typical two-hour window before detection. The change follows a September 2025 incident where poisoned npm packages (chalk, debug) reached 2 billion weekly downloads before removal.
This Wire brief sits within Fusion42's coverage of Enterprise Software, Cybersecurity and Data Infrastructure.
◆ ◆ The Wire takeaway
Your dependency automation now stops for three days to let malware get caught first. If you've configured Dependabot to auto-merge, you need to review that policy this week—the tool is no longer your speed advantage, it's your safety net.
◆ Coverage
1 source · 27 Jul 2026
◆ Related on Wire
◆ Topics