ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Web Emergency
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Time-Based Defences: GitHub and PyPI Slow Down Supply Chain Attacks

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Time-Based Defences: GitHub and PyPI Slow Dow...
  • All articles
  • Categories
  • Tags
  • Statuses

Time-Based Defences: GitHub and PyPI Slow Down Supply Chain Attacks

Why Time Is the New Defence in Software SecurityIn the ongoing battle against supply chain attacks, two major platforms have introduced a simple yet p...

Why Time Is the New Defence in Software Security

In the ongoing battle against supply chain attacks, two major platforms have introduced a simple yet powerful concept: delay. GitHub and PyPI have both implemented time-based barriers that give the community breathing room to spot malicious activity before it spreads. These changes reflect a growing recognition that speed can be an attacker's best ally, and that slowing down automated processes can significantly reduce risk.

Hourglass on server rack symbolising time-based security for software supply chains

Dependabot's 72-Hour Cooldown: A Pause for Thought

GitHub's Dependabot, the automated dependency management tool, now waits a default of 72 hours before opening pull requests for version updates. This cooldown period applies only to routine version bumps, not to security updates, which remain immediate. The rationale is straightforward: a newly released package version might contain undiscovered vulnerabilities or could even be a malicious upload from a compromised account. By forcing a pause, GitHub gives the broader community time to vet the release, reducing the likelihood that your project automatically adopts a dangerous update.

For development teams, this means adjusting expectations. Automated pull requests will no longer appear instantly when a new version is published. However, the cooldown is configurable via the cooldown option in the dependabot.yml file, allowing teams with strict maintenance windows or custom validation processes to tailor the delay to their needs. GitHub Enterprise Server will also receive this feature in version 3.23.

PyPI's 14-Day Window: Closing the Door on Version Poisoning

On the Python Package Index (PyPI), a different time-based defence has been enacted. As of July 8, 2026, PyPI rejects any attempt to upload new files to a release that is more than 14 days old. This measure targets a tactic known as "version poisoning," where attackers who compromise publishing credentials or CI/CD pipelines add malicious files to an older, stable release. Such actions can corrupt audits and break assumptions in build environments, as seen in incidents involving projects like LiteLLM and Telnyx earlier this year.

PyPI acknowledges that the ecosystem lacks standardised semantics for whether a release is "open" or "closed." Future initiatives like the Upload 2.0 API and Staged Previews aim to provide more flexible and secure upload mechanisms. In the meantime, maintainers must plan to publish all wheels and artefacts within the 14-day window. If support for a new Python version is needed later, the recommended approach is to release a new package version rather than modify an old one.

Practical Implications for Development Teams

These changes may seem minor, but they have significant implications for how teams manage dependencies and releases. Here are some key takeaways:

  • Embrace the 72-hour delay for Dependabot version updates. Use this time to run additional tests or manual reviews before merging.
  • Prioritise security updates – they remain immediate, so ensure your automated processes can distinguish between security and non-security patches.
  • Configure cooldown periods in dependabot.yml to align with your release cycles and validation requirements.
  • Strengthen lockfiles and pin dependencies to reduce unexpected changes in your package graph.
  • Plan PyPI releases carefully – ensure all artefacts are ready within 14 days of the initial release, and avoid the temptation to patch old versions.

Beyond Time Barriers: Essential Hygiene for Supply Chain Security

While these time-based defences are valuable, they are not a silver bullet. The real protection lies in robust security practices: using minimal permissions for tokens, rotating credentials regularly, implementing anti-fraud controls, and maintaining strict CI/CD hygiene. By combining these measures with the new platform-level delays, you can significantly reduce the attack surface and make it much harder for malicious code to slip through unnoticed.

For businesses in Spain and across the EU, where GDPR compliance and data integrity are paramount, adopting these practices is not just a technical necessity but a legal and reputational imperative. Whether you manage a small server fleet or a large hosting infrastructure, staying ahead of supply chain threats requires a proactive approach. Time-based defences are a welcome addition to the security toolkit, but they work best when integrated into a comprehensive security strategy.

Related

  • Gitea Critical Flaw: Git Hooks Open Door to Server Takeover
  • Cisco FMC zero-day exploited: what sysadmins must do now
  • Coldcard Flaw: How Weak Seed Entropy Led to a $88M Bitcoin Heist
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Compliance Consulting (GDPR, ENS, ISO 27001)
Performance Optimization
Virtualization & Containers (Docker, Kubernetes)
Cloud Migration (AWS, Azure, Google Cloud)
Process Automation (Scripts and Bots)
Relacionados
  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
    Cybersecurity · 1 day ago
  • Critical libssh2 flaw: urgent patch for SSH servers
    Cybersecurity · 1 day ago
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
    Cybersecurity · 1 day ago
  • FortiBleed: Guarding Your Perimeter Against Credential Harvesting
    Cybersecurity · 1 day ago
  • Browser Extensions: A Hidden Supply-Chain Risk for Your Servers
    Cybersecurity · 1 day ago
  • Critical LoadMaster RCE: What Sysadmins Must Do Now
    Cybersecurity · 1 day ago
Servidores MCP Destacados
  • Feishu/Lark OpenAPI
    Productivity
  • Shadcn UI MCP Server
    Development
  • Google Maps MCP Server
    Search
  • MCP Bridge API
    Development
  • MCP Doppler Server
    Cloud Service
  • Cursor Chat History MCP
    Development
  • omniparser-autogui-mcp
    Productivity
  • FastAPI with MCP
    Development
  • ScreenshotOne
    Web Scraping
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar