GitHub, PyPI add time-based defenses against supply chain attacks
CYBERSECURITY FEATURED ANALYSIS

GitHub, PyPI add time-based defenses against supply chain attacks

BY

Bill Toulas

SOURCE

BleepingComputer

DATE

READ

1 min read

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.