Dependabot version updates introduce default package cooldown
Dependabot now waits three days after a new release is available on its registry before opening version update pull requests, providing a default cooldown period to allow for detection of potential issues.
Dependabot now waits until a new release has been available on its registry for at least three days before opening a version update pull request. This cooldown is now the default and requires no configuration.
New releases are a common entry point for supply chain attacks where a compromised or broken version can reach your dependency updates before maintainers and the community have caught it. A short delay gives that signal time to surface, so you are less likely to merge a bad release the moment it ships.
A few things to know:
- The default applies only to version updates. Security updates still open immediately, so critical fixes are never delayed.
- You stay in control. Use the
cooldownoption in your.github/dependabot.ymlto set a different window or opt out entirely.
This default applies to Dependabot version updates across all supported ecosystems on github.com and will take effect in GitHub Enterprise Server (GHES) 3.23.
Learn more in our docs about Dependabot cooldowns.
The post Dependabot version updates introduce default package cooldown appeared first on The GitHub Blog.
Source: original entry ↗
More from GitHub
Follow GitHub to get its new changes in your feed and email digest.
Claude Haiku 5.5 now available in GitHub Copilot
Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.
Purpose-built model for leaked secret detection
GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.
Local sandboxing for GitHub Copilot now generally available
GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.