Commit 63d6571
authored
ci: configure dependabot cooldown (#15364)
Addresses the new zizmor alerts around this issue.
Waits a configurable number of days for a dependency to be released,
before creating a pull request for it. This is helpful when there are
supply chain security issues such as the recent NPM incidents.
https://docs.zizmor.sh/audits/#dependabot-cooldown1 parent 3389f2e commit 63d6571
1 file changed
+6
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
11 | 13 | | |
12 | 14 | | |
13 | 15 | | |
| |||
18 | 20 | | |
19 | 21 | | |
20 | 22 | | |
| 23 | + | |
| 24 | + | |
21 | 25 | | |
22 | 26 | | |
23 | 27 | | |
| |||
28 | 32 | | |
29 | 33 | | |
30 | 34 | | |
| 35 | + | |
| 36 | + | |
0 commit comments