GitHub and PyPI are implementing new cooldown periods for updates to prevent malicious packages from quickly infiltrating production systems. By delaying routine Dependabot requests and restricting modifications to older package releases, these platforms aim to create a wider discovery window for security scanners.