Dev Tools · 1h ago
Dependabot adds 3-day cooldown to slow version updates
GitHub's Dependabot now waits three days before issuing version update pull requests. The delay gives maintainers and security researchers time to address findings in a release before it reaches user code. The change aims to reduce risks from rushed dependency updates.
Meridian48 take
A sensible safety measure, but the real test is whether it meaningfully reduces incidents or just adds friction.
Read the full reporting
The case for a cooldown: Why Dependabot now waits before issuing version updates →
GitHub Blog
dependabotsupply-chain-security