Commit 0ceed88
committed
dependabot: set cooldown.default-days to 4
After further consideration, I'm convinced by the arguments in favor of
using dependency cooldowns to reduce exposure to supply-chain attacks:
https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
Remove suppression of https://docs.zizmor.sh/audits/#dependabot-cooldown
Signed-off-by: Kevin Locke <[email protected]>1 parent 3b6e0c4 commit 0ceed88
1 file changed
+6
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
| 5 | + | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
10 | 12 | | |
11 | 13 | | |
12 | 14 | | |
| 15 | + | |
| 16 | + | |
0 commit comments