megachangelog
Feature

Dependabot version updates introduce default package cooldown

Dependabot now waits three days after a new release is available on its registry before opening version update pull requests, providing a default cooldown period to allow for detection of potential issues.

Dependabot now waits until a new release has been available on its registry for at least three days before opening a version update pull request. This cooldown is now the default and requires no configuration.

New releases are a common entry point for supply chain attacks where a compromised or broken version can reach your dependency updates before maintainers and the community have caught it. A short delay gives that signal time to surface, so you are less likely to merge a bad release the moment it ships.

A few things to know:

  • The default applies only to version updates. Security updates still open immediately, so critical fixes are never delayed.
  • You stay in control. Use the cooldown option in your .github/dependabot.yml to set a different window or opt out entirely.

This default applies to Dependabot version updates across all supported ecosystems on github.com and will take effect in GitHub Enterprise Server (GHES) 3.23.

Learn more in our docs about Dependabot cooldowns.

The post Dependabot version updates introduce default package cooldown appeared first on The GitHub Blog.

dependabotsecurityautomationdependencies

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →