GitHub's Dependabot now applies a three-day cooldown for pull requests; PyPI blocks new files for releases over 14 days old.
GitHubPyPI

GitHub's Dependabot now applies a three-day cooldown for pull requests; PyPI blocks new files for releases over 14 days old.

GitHub's Dependabot now implements a three-day cooldown for pull requests to enhance security, allowing time to identify malicious updates. Concurrently, PyPI has introduced a policy blocking new files for releases older than 14 days, aiming to prevent potential attacks on trusted package versions.

DevOps.com DevOps.com27 July 2026 · 10:43 UTC
CuriousCats Full Story

GitHub's Dependabot has introduced a three-day cooldown before opening pull requests for routine version updates, enhancing security by allowing maintainers and automated scanners to detect malicious releases. This change follows previous updates to npm security and aims to mitigate risks in software supply chain security.13911

The cooldown period is crucial as the first few days after a release are often the most dangerous. GitHub emphasizes that this measure gives maintainers and researchers a chance to catch and remove malicious versions before they are integrated into projects.56

In parallel, PyPI has implemented a new policy that blocks new files from being added to releases older than 14 days. This preventative measure aims to reduce the risk of attackers poisoning trusted package versions, although PyPI has stated it is not aware of any real attacks utilizing this technique yet.2478

Data from PyPI indicates that the frequency of legitimate updates to old releases is minimal, with only a tiny fraction of popular packages needing to add new files after two weeks. This suggests that the new policy will not significantly disrupt normal operations while enhancing security.

GitHub continues to recommend pairing the cooldown with other security practices, such as using lockfiles for dependency pinning and limiting access tokens, to further safeguard against potential vulnerabilities.

Key Insight
“Dependabot's new three-day cooldown allows maintainers and scanners more time to detect malicious releases, enhancing security. Meanwhile, PyPI's restriction on adding new files to older releases aims to prevent potential attacks, although the platform has not yet seen this technique used in real incidents.”
CuriousCats studied:
1
DevOps.comDevOps.com
“Dependabot now waits three days by default before opening pull requests for routine version updates, giving maintainers and scanners more time to detect malicious releases.”
DevOps.com →
Ask CuriousCats
What is Dependabot's new cooldown period?
Why has PyPI restricted new files in releases?
How does this enhance software supply chain security?
Are there other platforms implementing similar measures?
How effective are cooldown periods in preventing attacks?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats