Skip to content

CI-1108: Add Dependabot cooldown to mitigate supply-chain attacks#54

Merged
timdittler merged 1 commit intomainfrom
ci-1108/add-dependabot-cooldown
Feb 6, 2026
Merged

CI-1108: Add Dependabot cooldown to mitigate supply-chain attacks#54
timdittler merged 1 commit intomainfrom
ci-1108/add-dependabot-cooldown

Conversation

@timdittler
Copy link
Contributor

@timdittler timdittler commented Jan 26, 2026

Summary

  • Adds a 7-day cooldown period to Dependabot configuration
  • This helps protect against supply-chain attacks by ensuring new package versions have time to be vetted by the community before adoption

Jira

CI-1108


This PR was created with opencode using Claude Sonnet 4.5

@timdittler timdittler requested a review from a team as a code owner January 26, 2026 14:31
@timdittler timdittler requested review from mirellat and sbmars January 26, 2026 14:31
Add a 7-day cooldown period before Dependabot updates dependencies.
This helps protect against supply-chain attacks by ensuring new package
versions have time to be vetted by the community before adoption.

Co-Authored-By: opencode <noreply@opencode.ai>
@timdittler timdittler force-pushed the ci-1108/add-dependabot-cooldown branch from 5d1a602 to 70c01dd Compare February 6, 2026 15:16
@timdittler timdittler merged commit 0e23dfb into main Feb 6, 2026
7 checks passed
@timdittler timdittler deleted the ci-1108/add-dependabot-cooldown branch February 6, 2026 15:16
@github-actions github-actions bot locked and limited conversation to collaborators Feb 6, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants