New GitHub, PyPI Policies Boost Supply Chain Security

SecurityWeek SecurityWeek

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.


The post https://www.securityweek.com/new-github-pypi-policies-boost-supply-chain-security/">New GitHub, PyPI Policies Boost Supply Chain Security appeared first on https://www.securityweek.com">SecurityWeek.

Read full article at SecurityWeek →