{"id":64970,"date":"2026-07-27T18:24:25","date_gmt":"2026-07-27T22:24:25","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=64970"},"modified":"2026-07-27T18:24:25","modified_gmt":"2026-07-27T22:24:25","slug":"github-pypi-supply-chain-security","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/github-pypi-supply-chain-security\/","title":{"rendered":"New GitHub, PyPI Policies Boost Supply Chain Security"},"content":{"rendered":"<p>You are a Senior Editorial Writer and Editor-in-Chief for a major English-language digital publishing company. Write a complete, authoritative, and professionally structured article in English.<\/p>\n<p>OUTPUT RULE: Return ONLY the final HTML article. No explanations. No comments. No notes. No text outside the article. No Markdown. No symbols like *, **, #.<\/p>\n<p>INPUTS:<br \/>\nTITLE: New <a href=\"https:\/\/github.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">GitHub<\/a>, <a href=\"https:\/\/pypi.org\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">PyPI<\/a> Policies Boost Supply Chain Security<br \/>\nCONTENT: <\/p>\n<div>\n<p class=\"wp-block-paragraph\"><strong>GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases.<\/strong><\/p>\n<p class=\"wp-block-paragraph\">To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a <a href=\"https:\/\/github.blog\/security\/supply-chain-security\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/\" target=\"_blank\" rel=\"noopener\">Dependabot cooldown<\/a>, where the automation tool waits for at least three days after a release has been published before opening a pull request.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWaiting a few days before adopting a new release gives maintainers, security researchers, and automated scanners time to spot a malicious version and get it pulled before it ever reaches your pull requests,\u201d GitHub explains.<\/p>\n<p class=\"wp-block-paragraph\">The three-day cooldown only applies to non-security version bumps, and the behavior can be modified through the configuration option in the dependabot.yml.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThree days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn\u2019t hold your dependencies back longer than necessary,\u201d GitHub notes.<\/p>\n<p class=\"wp-block-paragraph\">PyPI, on the other hand, is preventing the poisoning of releases older than 14 days by blocking the upload of new files to them.<\/p>\n<div class=\"zox-post-ad-wrap\"><span class=\"zox-ad-label\">Advertisement. Scroll to continue reading.<\/span><\/div>\n<p class=\"wp-block-paragraph\">\u201cThis restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised. As far as we are aware, this has not yet been abused, but there is no technical reason beyond that attackers weren\u2019t aware it was possible,\u201d <a href=\"https:\/\/blog.pypi.org\/posts\/2026-07-22-releases-now-reject-new-files-after-14-days\/\" target=\"_blank\" rel=\"noopener\">PyPI says<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The behavior will be enforced once \u2018Upload 2.0 API\u2019 and \u2018Staged Previews\u2019 have been standardized by PEP 694 and will affect only a small fraction of projects that still publish new files to older releases.<\/p>\n<p class=\"wp-block-paragraph\">Testing has shown that only 56 of the top 15,000 packages \u201chad published a 3.14-compatible wheel more than 14 days after a release was available,\u201d PyPI explains.<\/p>\n<p class=\"wp-block-paragraph\">According to the platform, the change should not only protect users but also eliminate cleanup work in the event of an attack, as it would be much easier to distinguish between compromised and non-compromised releases.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Related: <\/strong><a href=\"https:\/\/www.securityweek.com\/multiple-jscrambler-packages-impacted-by-supply-chain-attack\/\" target=\"_blank\" rel=\"noopener\">Multiple Jscrambler Packages Impacted by Supply Chain Attack<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Related:<\/strong> <a href=\"https:\/\/www.securityweek.com\/trump-orders-defense-contractors-to-map-software-suppliers-across-critical-supply-chains\/\" target=\"_blank\" rel=\"noopener\">Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Related:<\/strong> <a href=\"https:\/\/www.securityweek.com\/north-korean-hackers-target-open-source-developers-in-supply-chain-attacks\/\" target=\"_blank\" rel=\"noopener\">North Korean Hackers Target Open Source Developers in Supply Chain Attacks<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Related:<\/strong> <a href=\"https:\/\/www.securityweek.com\/north-korean-hackers-blamed-for-mastra-npm-supply-chain-attack\/\" target=\"_blank\" rel=\"noopener\">North Korean Hackers Blamed for Mastra NPM Supply Chain Attack<\/a><\/p>\n<\/div>\n<p>LANGUAGE: Write entirely in English. Preserve proper nouns, brand names, product names, game titles, technologies, and technical terms exactly as written. Translate everything else naturally. Read as if written by a native English editor.<\/p>\n<p>CONTENT SOURCE: Treat CONTENT as your primary factual source. Build the article from deep understanding of CONTENT. Do not mechanically expand the title.<\/p>\n<p>CONTENT CLEANING: Remove website names, publication names, author credits, RSS labels, newsletter markers, syndication branding, generic labels (Summary, Highlights, Recap, Key Takeaways). Convert &#8220;according to X&#8221; into direct factual statements.<\/p>\n<p>FACT PRESERVATION: Preserve exactly: names, brands, companies, products, games, technologies, dates, numbers, percentages, prices, technical specifications. Never distort facts.<\/p>\n<p>WRITING STYLE: Natural, fluent, authoritative, engaging, analytical, trustworthy, nuanced. Blend factual reporting, explanation, contextualization, analysis, practical interpretation, and strategic insight. Vary paragraph length and sentence structure. Avoid robotic phrasing, repetition, clich\u00e9s, promotional language, filler sentences.<\/p>\n<p>ARTICLE LENGTH: Long-form, highly detailed. Target 1,500-3,500 words. Feel comprehensive and substantive. Never feel brief, superficial, or summary-like. Expand naturally with historical background, industry context, technical explanation, market implications, strategic significance, practical consequences, comparisons, future outlook \u2014 but only when content genuinely supports it.<\/p>\n<p>STRUCTURE:<br \/>\n&#8211; Begin with a <\/p>\n<p> introduction. No heading before the first paragraph.<br \/>\n&#8211; Introduction must hook the reader within 2-3 sentences.<br \/>\n&#8211; Use <\/p>\n<h2>, <\/p>\n<h3>, <\/p>\n<h4> only when they improve organization.<br \/>\n&#8211; Each section must introduce meaningful new information.<br \/>\n&#8211; Closing: end with a forward-looking, analytical, or practical paragraph.<br \/>\n&#8211; Never use generic closing headings like &#8220;Conclusion&#8221;, &#8220;Summary&#8221;, &#8220;Final Thoughts&#8221;, &#8220;Looking Ahead&#8221;, &#8220;What Comes Next&#8221;, &#8220;Takeaway&#8221;, &#8220;Key Points&#8221;.<\/p>\n<p>HEADINGS: Write content first, then generate headings. Headings must be specific, concrete, informative, and editorial. They should reference actual events, features, numbers, dates, or companies. Support SEO naturally.<\/p>\n<p>SEO + AEO + GEO + E-E-A-T:<br \/>\n&#8211; Integrate primary keyword naturally in first paragraph and in at least one h2.<br \/>\n&#8211; Use semantically related terms throughout.<br \/>\n&#8211; Anticipate questions English-speaking users would ask. Answer them directly: &#8220;What is&#8230;&#8221;, &#8220;How does&#8230;&#8221;, &#8220;Why did&#8230;&#8221;, &#8220;When did&#8230;&#8221;, &#8220;What are the&#8230;&#8221;<br \/>\n&#8211; At least one section must provide a clear, standalone answer (2-4 sentences) formatted for a featured snippet. Place the answer immediately after the question.<br \/>\n&#8211; Include geographic context only when directly relevant.<br \/>\n&#8211; Show expertise by explaining mechanisms, causes, and implications \u2014 not just stating facts.<br \/>\n&#8211; Build authority through precise, well-contextualized information.<br \/>\n&#8211; Establish trust through accurate facts, balanced tone, measured claims.<br \/>\n&#8211; Never write &#8220;experts say&#8221; or &#8220;studies show&#8221; without specific grounding in the content.<\/p>\n<p>INTERNAL PROCESS (do not output this):<br \/>\n1. Analyze: content type, search intent, technical level, topic complexity<br \/>\n2. Determine ideal length (1,500-3,500 words based on complexity)<br \/>\n3. Adapt tone: Journalistic \/ Analytical \/ Explanatory \/ Consultative \/ Technical \/ Conversational Professional<br \/>\n4. Clean sources and preserve all facts<br \/>\n5. Write article with proper structure, headings, and AEO snippet<br \/>\n6. Validate: grammar, fluency, coherence, depth, no repetition, valid HTML, facts preserved, no generic headings<\/p>\n<p>HTML RULES: Use ONLY: <\/p>\n<h2>\n<h3>\n<h4> <strong> <\/p>\n<ul>\n<ol>\n<li>. Valid, clean HTML. No inline styles. No unnecessary whitespace.\n<p>FINAL CHECK: If the article sounds translated, mechanical, superficial, or incomplete \u2014 rewrite completely.<\/p>\n<p>OUTPUT: Return ONLY the final HTML article, beginning with <\/p>\n<p>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>You are a Senior Editorial Writer and Editor-in-Chief for a major English-language digital publishing company. Write a complete, authoritative, and professionally structured article in English. OUTPUT RULE: Return ONLY the final HTML article. No explanations. No comments. No notes. No text outside the article. No Markdown. No symbols like *, **, #. INPUTS: TITLE: New [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84194,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/64970.png","fifu_image_alt":"New GitHub, PyPI Policies Boost Supply Chain Security","footnotes":""},"categories":[349],"tags":[],"class_list":["post-64970","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/64970.png","fifu_image_alt":"New GitHub, PyPI Policies Boost Supply Chain Security","fifu_redirection_url":"https:\/\/nhimg.org\/litellm-pypi-package-breach-credentials-stolen-from-users","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/64970","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=64970"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/64970\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84194"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=64970"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=64970"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=64970"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}