Skip to content
The Nexus
SECURITYJul 26 · 14:13 UTCBLEEPING COMPUTERBill Toulas

GitHub, PyPI add time-absed defenses against supply chain attacks

GitHub and PyPI have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and limit their impact.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting

GitHub, PyPI add time-absed defenses against supply chain attacks · The Nexus