Skip to content

chore(deps): add a 7-day Dependabot cooldown to version updates - #15

Open
devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1785815752-dependency-cooldown-7d
Open

chore(deps): add a 7-day Dependabot cooldown to version updates#15
devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1785815752-dependency-cooldown-7d

Conversation

@devin-ai-integration

Copy link
Copy Markdown

🤖 Created in Devin (session) by @Utkarsh-AL

Requested in this Slack thread.

Summary

Adds cooldown: {default-days: 7} to the entry in .github/dependabot.yml, so Dependabot will not open a version-bump PR for a release until it is 7 days old.

Compromised npm/Go/Docker/Actions releases are typically yanked within hours to a few days of publication. Delaying automated version-bump PRs by 7 days means Dependabot never proposes a release during the window in which most supply-chain attacks are discovered.

cooldown applies to version updates only — Dependabot security updates are never delayed by it.

Matches the existing convention in angellist/boba. Config-only; verified the file still parses as YAML.

@devin-ai-integration

Copy link
Copy Markdown
Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant