Skip to content

Add cooldown to Dependabot version upgrades#155

Merged
khk-globus merged 1 commit intomainfrom
dependabot-cooldown-sc-47428
Feb 18, 2026
Merged

Add cooldown to Dependabot version upgrades#155
khk-globus merged 1 commit intomainfrom
dependabot-cooldown-sc-47428

Conversation

@chris-janidlo
Copy link
Contributor

Cooldowns give package repository maintainers time to mitigate supply chain attacks before those attacks reach us. The period of 7 days was chosen based on some informal research in the blog post that motivated this change.

https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns

@chris-janidlo chris-janidlo added no-news-is-good-news This change does not require a news file quick-review labels Feb 18, 2026
Cooldowns give package repository maintainers time to mitigate supply
chain attacks before those attacks reach us. The period of 7 days was
chosen based on some informal research in the blog post that motivated
this change.

https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
@chris-janidlo chris-janidlo force-pushed the dependabot-cooldown-sc-47428 branch from dec21b0 to dd4dee0 Compare February 18, 2026 16:48
@chris-janidlo chris-janidlo marked this pull request as ready for review February 18, 2026 16:50
@khk-globus khk-globus merged commit 5affb22 into main Feb 18, 2026
12 checks passed
@khk-globus khk-globus deleted the dependabot-cooldown-sc-47428 branch February 18, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-news-is-good-news This change does not require a news file quick-review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants