Skip to content

Conversation

@timdittler
Copy link
Contributor

@timdittler timdittler commented Jan 26, 2026

Summary

  • Adds a 7-day cooldown period to Dependabot configuration
  • This helps protect against supply-chain attacks by ensuring new package versions have time to be vetted by the community before adoption

Jira

CI-1108


This PR was created with opencode using Claude Sonnet 4.5

Add a 7-day cooldown period before Dependabot updates dependencies.
This helps protect against supply-chain attacks by ensuring new package
versions have time to be vetted by the community before adoption.

Co-Authored-By: opencode <noreply@opencode.ai>
@timdittler timdittler merged commit ee8ec8a into main Jan 26, 2026
7 checks passed
@timdittler timdittler deleted the ci-1108/add-dependabot-cooldown branch January 26, 2026 15:54
@github-actions github-actions bot locked and limited conversation to collaborators Jan 26, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants