← Back

Wire · technology

GitHub implements version update delay so security issues can be caught

Published

27 July 2026

Topic

technology

Sectors

Enterprise SoftwareCybersecurity

Geography

United States

Source

Read at betanews.com

Verified

Fusion42 · 27 July 2026 · Fusion42 review

GitHub's Dependabot now enforces a three-day cooldown by default on version updates (excluding security patches), giving security researchers time to detect malware in newly released packages before widespread adoption. The change responds to supply-chain attacks where malicious versions have historically been caught and removed within hours.

This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

If you distribute packages or tools via npm, PyPI, or similar registries, your window to catch and pull a poisoned release before mass infection just shrank from hours to minutes—and GitHub's default now assumes your users won't adopt your updates for three days. Reconsider your release frequency and testing pipeline; slow release cycles now protect you, but fast ones leave you exposed.

Related on Wire

Topics

Enterprise SoftwareCybersecuritydependency-securitysupply-chain-attackmalware-detectiondevops-workflowopen-source-risk