
GitHub Adds Three-Day Dependabot Cooldown to Block Supply Chain Attacks
GitHub has rolled out a new default security control for Dependabot, introducing a three-day cooldown period before version update pull requests are opened. The change, announced by GitHub’s Carlin Cherry on July 23, 2026, directly targets a growing supply chain attack pattern where malicious code rides in on freshly published package versions and gets automatically […]
The post GitHub Adds Three-Day Dependabot Cooldown to Block Supply Chain Attacks appeared first on Cyber Security News.