New GitHub, PyPI Policies Hope to Boost Supply Chain Security
新GitHub与PyPI政策有望加强供应链安全
来源: securityweek.com | 主题: Programming | 评论: 3
时间: on Saturday August 01, 2026 @01:00PM
"GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security," reports SecurityWeek , "by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases." To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a Dependabot cooldown , where the automation tool waits for at least three days after a release has been published before opening a pull request. "Waiting a few days before adopting a new release gives maintainers, security researchers, and automated scanners time to spot a malicious version and get it pulled before it ever reaches your pull requests," GitHub explains. The three-day cooldown only applies to non-security v
⋯ 继续阅读请登录会员 ⋯