GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates
GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automatically adopting new malicious packages. This change targets a prevalent pattern in software supply chain attacks where attackers compromise a trusted package maintainer’s account, publish a malicious update, and rely on automated dependency tools to distribute it […]
The post GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates appeared first on Cyber Security News.