GitHub, PyPI add time-absed defenses against supply chain attacks

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. The integration of time-based defenses by major code repositories and package managers like GitHub and PyPI is a significant step in fortifying the software supply chain.

https://meta-news.info/ver/github-pypi-add-time-absed-defenses-againstโ€ฆ