•1 min read•from InfoQ
GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates


Instead of immediately opening pull requests when newer dependency versions are released, Dependabot now waits three days before suggesting upgrades, thus increasing the likelihood that malicious releases are identified and removed before they can be integrated.
By Sergio De SimoneWant to read more?
Check out the full article on the original site
Tagged with
#Dependabot
#dependency versions
#pull requests
#GitHub
#security
#malicious releases
#version updates
#cooldown policy
#integration
#releases
#vulnerability detection
#software supply chain
#dependency management
#security policy
#automated updates
#code security
#continuous integration
#package management
#open source
#automation