Sign up for our newsletter!
Stay informed on the latest DevOps news
DevOps.com
Latest
Articles
Features
Most Read
News
News Releases
Topics
AI
Continuous Delivery
Continuous Testing
Cloud
Culture
DataOps
DevSecOps
Enterprise DevOps
Leadership Suite
DevOps Practice
ROELBOB
DevOps Toolbox
IT as Code
Videos/Podcasts
Techstrong.tv Podcast
Techstrong.tv - Twitch
DevOps Unbound
Webinars
Upcoming
Calendar View
On-Demand Webinars
Library
Events
Upcoming Events
On-Demand Events
Sponsored Content
Related Sites
Techstrong Group
Cloud Native Now
Security Boulevard
Platform Engineering
Techstrong Research
DevOps Dozen
DevOps TV
Techstrong TV
Techstrong.tv Podcast
Techstrong.tv - Twitch
Media Kit
About
Sponsor
AI
Cloud
CI/CD
Continuous Testing
DataOps
DevSecOps
DevOps Onramp
Platform Engineering
Low-Code/No-Code
IT as Code
More
Serverless on AWS
Builder Community Hub
Application Performance Management/Monitoring
Culture
Enterprise DevOps
ROELBOB
Tag:
Python Package Index
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
Tom Smith
|
July 27, 2026
|
automated updates
,
CI/CD security
,
dependency cooldown
,
dependency pinning
,
dependency updates
,
devops security
,
GitHub Dependabot
,
lockfiles
,
malicious packages
,
open source security
,
package poisoning
,
package registry security
,
platform engineering
,
PyPi
,
Python Package Index
,
scoped access tokens
,
Software Supply Chain Security
,
supply chain attacks
GitHub and PyPI are using time as a security control, delaying dependency updates and locking older releases against new file uploads ...
×