GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates

GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automatically adopting new malicious packages. This change targets a prevalent pattern in software supply chain attacks where attackers compromise a trusted package maintainer’s account, publish a malicious update, and rely on automated dependency tools to distribute it […]

This article has been indexed from Cyber Security News

Read the original article: