
GitHub and PyPI add time-delay defenses against supply chain attacks
GitHub's Dependabot now waits 72 hours before adopting new package versions, and PyPI blocks new file uploads to releases older than 14 days — both measures aimed at the wave of malicious package attacks that hit npm and PyPI over the past year.










