1 min readfrom InfoQ

GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates

GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates

Instead of immediately opening pull requests when newer dependency versions are released, Dependabot now waits three days before suggesting upgrades, thus increasing the likelihood that malicious releases are identified and removed before they can be integrated.

By Sergio De Simone

Want to read more?

Check out the full article on the original site

View original article

Tagged with

#Dependabot
#dependency versions
#pull requests
#GitHub
#security
#malicious releases
#version updates
#cooldown policy
#integration
#releases
#vulnerability detection
#software supply chain
#dependency management
#security policy
#automated updates
#code security
#continuous integration
#package management
#open source
#automation