GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks July 27, 2026 by Tom Smith GitHub and PyPI are using time as a security control, delaying dependency updates and locking older releases against new file uploads.