Skip to content

Conversation

@Garbee
Copy link
Member

@Garbee Garbee commented Aug 4, 2025

This applies the new cooldown option for dependabot. It will hold updates until after they have been out for at least a week. This will allow a reasonable time for packages to exist and if any issues exist in the supply chain, get caught before the updates come through.

No QA Needed
Refs: https://github.com/dequelabs/axe-api-team/issues/598

This applies the new [cooldown option](https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference#cooldown-) for dependabot. It will hold updates until after they have been out for at least a week. This will allow a reasonable time for packages to exist and if any issues exist in the supply chain, get caught before the updates come through.

No QA Needed
Refs: dequelabs/axe-api-team#598
@Garbee Garbee self-assigned this Aug 4, 2025
Copilot AI review requested due to automatic review settings August 4, 2025 20:52
@Garbee Garbee requested a review from a team as a code owner August 4, 2025 20:52
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR configures Dependabot to use a 7-day cooldown period for dependency updates, adding a safety buffer to allow time for newly released packages to be vetted before automatic updates are applied.

  • Adds cooldown configuration to delay dependency updates by 7 days after release
  • Enhances supply chain security by providing time for issues to be discovered in new package versions

@Garbee Garbee merged commit c78eb9b into main Aug 4, 2025
6 checks passed
@Garbee Garbee deleted the garbee/dependabot/cooldown branch August 4, 2025 21:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants