Story thread · 2 reports / 2 sources

GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates

infoq.com · 14d

How the coverage leans

Across 2 sources · syndicated copies counted once

Instead of immediately opening pull requests when newer dependency versions are released, Dependabot now waits three days before suggesting upgrades, thus increasing the likelihood that malicious releases are identified and removed before they can be integrated. By Sergio De Simone

First report: GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption thehackernews.com, 15d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.