Security · 2h ago
GitHub Adds 3-Day Dependabot Cooldown to Curb Poisoned Package Risks
GitHub now lets Dependabot wait at least three days after a release before opening a pull request, giving time to detect malicious updates. The cooldown is configurable via dependabot.yml. The move aims to limit adoption of poisoned packages in automated dependency updates.
Meridian48 take
The cooldown is a sensible guardrail, but its effectiveness depends on how quickly the community flags malicious releases within that window.
Read the full reporting
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption →
The Hacker News
dependency-managementsupply-chain-security