Skip to content

Add per-language supply chain attack prevention via default cooldowns#3791

Open
pid1 wants to merge 1 commit intosemgrep:developfrom
pid1:develop
Open

Add per-language supply chain attack prevention via default cooldowns#3791
pid1 wants to merge 1 commit intosemgrep:developfrom
pid1:develop

Conversation

@pid1
Copy link
Copy Markdown

@pid1 pid1 commented Mar 27, 2026

Require cooldowns or minimum release ages before updating to newly published package versions.

This covers:

  • Dependabot
  • Renovate
  • pnpm
  • uv

Additionally, detect unpinned dependencies in Python scripts using uv’s inline script metadata format.

@CLAassistant
Copy link
Copy Markdown

CLAassistant commented Mar 27, 2026

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants