New GitHub, PyPI Policies Boost Supply Chain Security
CYBERSECURITY FEATURED ANALYSIS

New GitHub, PyPI Policies Boost Supply Chain Security

BY

Ionut Arghire

SOURCE

SecurityWeek

DATE

READ

1 min read

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on …

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek.