From 3f44a703151eb8c54c1bb93734163dbe5ad5e27f Mon Sep 17 00:00:00 2001 From: lj-n <40147557+lj-n@users.noreply.github.com> Date: Tue, 11 Aug 2026 15:16:29 +0200 Subject: [PATCH] chore(renovate): apply a 3-day minimumReleaseAge cooldown to updates (#391) Renovate now waits 3 days after a release is published before opening or automerging an update PR for it, giving the ecosystem time to detect and unpublish compromised versions. Security remediation PRs keep Renovate's default bypass of the cooldown, documented explicitly in the config. Co-Authored-By: Claude Fable 5 --- renovate.json | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/renovate.json b/renovate.json index b9f6a92c..60149f79 100644 --- a/renovate.json +++ b/renovate.json @@ -2,7 +2,13 @@ "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": ["config:recommended", "group:allNonMajor", "schedule:weekly"], "timezone": "Europe/Berlin", + "description": "minimumReleaseAge: wait 3 days after a version is published before updating to it, so compromised releases can be detected and unpublished before they land here.", + "minimumReleaseAge": "3 days", "osvVulnerabilityAlerts": true, + "vulnerabilityAlerts": { + "description": "Security remediation PRs deliberately skip the 3-day cooldown (Renovate's default): a known vulnerability in the currently used version outweighs the supply-chain wait for the fixed version.", + "minimumReleaseAge": null + }, "lockFileMaintenance": { "enabled": true },