Donation Amount. Min £4.99

By Ravie Lakshmanan - The Hacker News

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request.

"The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project," the Microsoft-owned subsidiary said.

According to GitHub, the three-day cooldown default only applies to version updates, which are designed to keep software dependencies up-to-date. Security updates will continue to be pushed right away, permitting Dependabot to issue an alert and open a pull request to move the project to the patched version.

With this update, the idea is to handle scenarios where a threat actor manages to push a poisoned version of a popular package, which then gets quickly pulled by downstream projects before that version is yanked from the registry. Although such trojanized packages are short-lived, the time period for which they remain accessible is enough to expand the blast radius of a supply chain attack.

GitHub said it arrived at three days as the default as it considers the duration to be in the goldilocks zone. "Three days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn't hold your dependencies back longer than necessary," it added.

At the same time, the software development platform emphasized that the control should be just one layer of defense among several others, including pinning dependencies with lockfiles, disabling install scripts in CI, scoping the tokens in build pipelines, and reviewing updates before they merge.

"A cooldown is built for a specific pattern: a malicious version that ships, spreads, and gets caught quickly," GitHub said. "It does little against attacks that play a longer game, including backdoors planted in releases and left dormant, maintainer sabotage, or a compromised build system."

It's worth noting similar cooldown controls have been announced across various package ecosystems over the past year, including Microsoft Visual Studio Code (VS Code), Ruby, Bun, npm, pnpm, and Yarn.

GitHub's time-based defense comes as the maintainers of the Python Package Index (PyPI) announced plans to block maintainers from adding new files to a package release after 14 days have passed since its publication.

"The measure is intended to prevent attackers who compromise publishing tokens or workflows from poisoning old, trusted releases," PyPI noted. 

Found this article interesting? Follow us on Google NewsTwitter and LinkedIn to read more exclusive content we post.

About IEA Media Ltd

Informer East Africa is a UK based diaspora Newspaper. It is a unique platform connecting East Africans at home and abroad through news dissemination. It is a forum to learn together, grow together and get entertained at the same time.

To advertise events or products, get in touch by info [at] informereastafrica [dot] com or call +447957636854.
If you have an issue or a story, get in touch with the editor through editor[at] informereastafrica [dot] com or call +447886544135.

We also accept donations from our supporters. Please click on "donate". Your donations will go along way in supporting the newspaper.

Get in touch

Our Offices

London, UK
+44 7886 544135
editor (@) informereastafrica.com
Slough, UK
+44 7957 636854
info (@) informereastafrica.com

Latest News

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub Adds 3-Day De...

By Ravie Lakshmanan - The Hacker News GitHub has announced a new cooldown mechanism in Dependabot, a...

PM meets Ugandan minister

PM meets Ugandan min...

Prime Minister and Minister of Foreign Affairs HE Sheikh Mohammed bin Abdulrahman bin Jassim Al Than...

Somalia: When Mobile Money Came Before Modern Banking

Somalia: When Mobile...

By Richie Santosdiaz The following is an in-depth analysis of the fintech and wider digital economi...

 7 missing as speedboat vanishes crossing Lake Malawi from Tanzania

7 missing as speedbo...

Speedboat carrying four foreign nationals vanishes on Lake Malawi The Tanzanian-registered vessel,...

For Advertisement

Big Reach

Informer East Africa is one platform for all people. It is a platform where you find so many professionals under one umbrella serving the African communities together.

Very Flexible

We exist to inform you, hear from you and connect you with what is happening around you. We do this professionally and timely as we endeavour to capture all that you should never miss. Informer East Africa is simply news for right now and the future.

Quality News

We only bring to you news that is verified, checked and follows strict journalistic guidelines and standards. We believe in 1. Objective coverage, 2. Impartiality and 3. Fair play.

Banner & Video Ads

A banner & video advertisement from our sponsors will show up every once in a while. It keeps us and our writers coffee replenished.