Skip to content

Conversation

steveoh
Copy link
Member

@steveoh steveoh commented Jul 29, 2025

This PR adds cooldown settings to the dependabot configuration for all package ecosystems.

What this does:

  • Allows dependabot to delay including dependencies for a configurable number of days.

Benefits:

  • The community finds supply chain vulnerabilities and bugs before they are included in a pull request.

@stdavis stdavis merged commit 8be5073 into main Jul 30, 2025
3 checks passed
@stdavis stdavis deleted the ci/cooldown-dependabot branch July 30, 2025 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants