< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-27T13:31:23+05:30

GitHub Implements 3-Day Dependabot Cooldown to Mitigate Supply Chain Attack Risks

GitHub introduced a 3-day cooldown period for Dependabot's version update PRs to mitigate supply chain risks from malicious package adoption, while maintaining immediate security updates. The change aims to balance proactive dependency management with defense against short-lived trojanized packages.

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request.

"The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project," the Microsoft-owned subsidiary said.

According to GitHub, the

Read original article

*** END OF TRANSMISSION ***