GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update [β¦]
The post GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



