New Time-Based Defenses from GitHub and PyPI: 72-Hour Cooldown and 14-Day Block Against Supply Chain Attacks

Discover how GitHub and PyPI's new time-based defenses, including a 72-hour cooldown and 14-day block, protect against supply chain attacks.

New Time-Based Defenses from GitHub and PyPI: 72-Hour Cooldown and 14-Day Block Against Supply Chain Attacks
Vulnerabilities

Illustrative image generated with AI

Introduction

Software supply chain protection is at the forefront of developers' and distribution platforms' concerns. On July 26, 2026, GitHub and PyPI introduced two time-based mechanisms to counter recent malicious campaigns targeting the npm and Python ecosystems. GitHub integrated a default 72-hour cooldown into Dependabot for automatic update pull requests, while PyPI now prohibits uploading additional files to a release after 14 days from the initial publication. Both measures stem from the need to slow down attackers and reduce the exposure window, reacting to threats like “chalk”/“debug”, “s1ngularity”, Shai-Hulud, and GhostAction.

Technical Analysis

Dependabot's Cooldown on GitHub

Dependabot, GitHub's automatic dependency update tool, now waits 72 hours before opening a pull request when it detects a new package version. This delay, configurable in the .github/dependabot.yml file, is intended to give security tools and the community time to identify suspicious or malicious packages. The initiative strengthens previous npm interventions and directly responds to attack techniques that leveraged the immediacy of automatic updates to propagate malicious code. Since Dependabot analyzes manifests (e.g., package.json) and registry feeds, the cooldown acts by postponing PR creation: if a package is flagged and removed within the first hours, automatic updates won't adopt it.

Post-Publication Block on PyPI

The Python Package Index introduced a strict time limit: from the initial publication of a release, maintainers have 14 days to add files; after that window, the upload API returns an error. This choice is preventive: although no real attacks based on poisoning old releases have been observed, metadata analysis shows that only a negligible fraction of projects legitimately upload files after two weeks, making the constraint acceptable. Technically, PyPI checks the release creation date and blocks any modification attempt beyond the limit, reducing the risk that an attacker with compromised credentials injects malware into “historic” and trusted versions.

Impact

The time-based mechanisms significantly raise the bar for attackers and mitigate two high-severity scenarios:

  • Dependabot cooldown: without this delay, a malicious package could be automatically propagated to thousands of repositories through pull requests opened within minutes, before maintainers and threat intelligence systems block it. The 72 hours provide a vital buffer for defenses.
  • PyPI block: poisoning a well-established release would allow an attacker to target those installing that version, relying on its reputation. The 14-day limit makes it impossible to tamper with older releases, protecting long-term package integrity and simplifying response to potential account compromises.

The severity is high because recent campaigns have shown how just minutes can lead to large-scale compromises, including credential theft and malware distribution in CI/CD and development environments.

Mitigation

These are the currently enforced countermeasures and complementary recommendations:

  • Dependabot cooldown (active by default): 72-hour wait before automatically opening PRs. It is configurable, but complete removal is discouraged; if fast updates are needed, it can be reduced, accompanied by additional manual checks.
  • PyPI block (automatic and universal): no action required from maintainers. The system automatically prevents late uploads on all releases.
  • Complementary practices (recommended by GitHub and the community):
    • Use lockfiles (e.g., package-lock.json, Pipfile.lock) to pin dependencies to exact, known-safe versions.
    • Use scoped tokens in CI/CD to limit installation privileges.
    • Disable unnecessary scripts during installation (e.g., --ignore-scripts for npm, Python virtual environments without automatic setup.py execution).
    • Test active defenses: conduct attack simulations to verify that SIEM and EDR detect package tampering, reducing false negatives.

FAQ

1. Can I disable the Dependabot cooldown if my project needs immediate updates?

Yes, you can modify the open-pull-requests-limit parameter and the wait value in the Dependabot configuration file, or disable it entirely. However, doing so exposes you to high risks: if you choose this path, you must compensate with manual scanning of new versions and strict CI security policies.

2. Does the 14-day block on PyPI apply to packages I published months ago?

Yes, the rule is retroactive regarding adding new files. If you try to upload a file to a release created more than 14 days ago, PyPI's API will return an error, regardless of when the measure was introduced. Existing releases are not altered, but they are no longer modifiable.

3. Are these time-based mechanisms enough to protect the supply chain?

No. Time-based defenses reduce the attack surface and slow attackers, but they must be integrated into a broader strategy: lockfiles, continuous dependency monitoring, least-privilege CI/CD, and team training remain essential. Threats evolve quickly and require a multi-layered approach.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →