devops.com
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks - DevOps.com
GitHub’s Dependabot now defaults to a three-day cooldown before opening pull requests for routine version updates, while PyPI will no longer accept new files for releases older than 14 days. Both chan…