← Back

Wire · technology

GitHub Adds Three-Day Dependabot Cooldown to Block Supply Chain Attacks

Published

27 July 2026

Topic

technology

Sectors

Developer ToolsCybersecurity

Geography

United States

Source

Read at cyberpress.org

Verified

Fusion42 · 27 July 2026 · Fusion42 review

GitHub has introduced a three-day default cooldown for Dependabot version updates to delay automated dependency pulls and block malicious packages before they spread through build pipelines. The feature responds to supply chain attacks where trojanized packages are detected and removed within hours, but fast enough to compromise systems before human review.

This Wire brief sits within Fusion42's coverage of Developer Tools and Cybersecurity, and 7 sources have reported it between 27 Jul 2026 and 31 Jul 2026.

◆ The Wire takeaway

If you're selling software security, vulnerability scanning, or SCA tooling to enterprise teams, your customers just got a built-in competitive threat. GitHub is now doing your job for free—at least for the low-hanging malicious packages. The opening: teams still need to manage the backdoors GitHub's cooldown doesn't catch, and they need visibility into the three-day window itself.

Coverage

7 sources · first reported 27 Jul 2026 · latest 31 Jul 2026

Related on Wire

Topics

Developer ToolsCybersecuritydependabotsupply-chain-securitynpm-malwaredependency-managementbuild-pipeline-security