Skip to content

Conversation

@timdittler
Copy link

@timdittler timdittler commented Jan 26, 2026

Summary

  • Adds a 7-day cooldown period to Dependabot configuration
  • This helps protect against supply-chain attacks by ensuring new package versions have time to be vetted by the community before adoption

Jira

CI-1108


This PR was created with opencode using Claude Sonnet 4.5

Add a 7-day cooldown period before Dependabot updates dependencies.
This helps protect against supply-chain attacks by ensuring new package
versions have time to be vetted by the community before adoption.

Co-Authored-By: opencode <noreply@opencode.ai>
@timdittler timdittler requested a review from a team as a code owner January 26, 2026 15:23
@timdittler timdittler enabled auto-merge (squash) January 26, 2026 16:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants