SECURITYBLEEPING COMPUTER
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and limit their impact.
Related Signal
Adjacent reporting
- AI-Assisted Supply Chain Attack Targets GitHub
- GitHub announces npm security changes to tackle supply-chain attacks
- The never-ending supply chain attacks worm into SAP npm packages, other dev tools
- PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials
- Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack