Skip to content

chore: add dependabot cooldown settings to mitigate ongoing supply chain attacks#319

Merged
oscarmuhr merged 1 commit intomasterfrom
add-dependabot-cooldown
Mar 31, 2026
Merged

chore: add dependabot cooldown settings to mitigate ongoing supply chain attacks#319
oscarmuhr merged 1 commit intomasterfrom
add-dependabot-cooldown

Conversation

@Tethik
Copy link
Copy Markdown
Contributor

@Tethik Tethik commented Mar 31, 2026

Summary

Adds cooldown configuration to every package ecosystem in .github/dependabot.yml to reduce exposure to ongoing supply chain attacks by limiting how quickly compromised or malicious package versions can be automatically adopted.

  • default-days: 7 — general cooldown between updates
  • semver-major-days: 30 — slow down disruptive major bumps
  • semver-minor-days: 7 — moderate cadence for minor releases
  • semver-patch-days: 3 — quick turnaround for patch/security fixes

Test plan

  • Verify dependabot.yml is valid YAML after the change
  • Confirm all updates entries now contain a cooldown block

@Tethik Tethik requested a review from a team as a code owner March 31, 2026 06:25
@oscarmuhr oscarmuhr merged commit f67c08d into master Mar 31, 2026
1 check passed
@oscarmuhr oscarmuhr deleted the add-dependabot-cooldown branch March 31, 2026 07:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants