Skip to content

Conversation

@tmathern
Copy link
Contributor

@tmathern tmathern commented Nov 26, 2025

Changes in this pull request

Add a cooldown to dependabot before it suggests PRs for updates.
Reference docs: https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference

I set a cooldown for all dependencies ("default") to 7 days, we can fine tune later (eg. 30 days for major versions) if we think we need that kind of fine-tuning.

ps: If we ever need, we can exclude dependencies from the cooldown too.

Checklist

  • This PR represents a single feature, fix, or change.
  • All applicable changes have been documented.
  • Any TO DO items (or similar) have been entered as GitHub issues and the link to that issue has been included in a comment.

@codspeed-hq
Copy link

codspeed-hq bot commented Nov 27, 2025

CodSpeed Performance Report

Merging #1632 will not alter performance

Comparing mathern/dependabot-cooldown (a3cc8c7) with main (352a968)

Summary

✅ 16 untouched
⏩ 2 skipped1

Footnotes

  1. 2 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants