Commit aa025a6
committed
Adopt 7 day cooldown before upgrading dependencies
In an effort to reduce the risk of a supply chain attack, add a 7 day
cooldown between when a new version of a dependency is released and when
Dependabot creates a PR upgrating to it.
Most malicious packages are detected by package vendors (in our case,
NPM) relatively quickly. The damage is done in the window between when a
malicious package is released, and when it is identified and taken down.
By adding a cooldown we narrow the window where a malicious package can
be introduced, and hopefully within 7 days this window shrinks to zero
and we have no potential exposure at all. At minimum this cooldown
shrinks the window we're vulnerable.
For a more detailed explanation of how this helps, see:
https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns1 parent 93ed7ef commit aa025a6
1 file changed
+2
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
7 | 9 | | |
8 | 10 | | |
9 | 11 | | |
| |||
0 commit comments