Skip to content

Commit 63d6571

Browse files
authored
ci: configure dependabot cooldown (#15364)
Addresses the new zizmor alerts around this issue. Waits a configurable number of days for a dependency to be released, before creating a pull request for it. This is helpful when there are supply chain security issues such as the recent NPM incidents. https://docs.zizmor.sh/audits/#dependabot-cooldown
1 parent 3389f2e commit 63d6571

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

.github/dependabot.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,8 @@ updates:
88
commit-message:
99
prefix: ci
1010
labels: [dependencies, skip-changelog]
11+
cooldown:
12+
default-days: 7
1113

1214
# python dependencies in /dev-tools/scripts
1315
- package-ecosystem: pip
@@ -18,6 +20,8 @@ updates:
1820
commit-message:
1921
prefix: build(deps)
2022
labels: [dependencies, skip-changelog]
23+
cooldown:
24+
default-days: 7
2125

2226
- package-ecosystem: gradle
2327
directory: /
@@ -28,3 +32,5 @@ updates:
2832
commit-message:
2933
prefix: deps(java)
3034
labels: [dependencies, skip-changelog]
35+
cooldown:
36+
default-days: 7

0 commit comments

Comments
 (0)