Skip to content

ci: add cooldown to dependabot#15796

Merged
kevinjqliu merged 1 commit intoapache:mainfrom
kevinjqliu:kevinjqliu/zizmor-dependabot
Mar 27, 2026
Merged

ci: add cooldown to dependabot#15796
kevinjqliu merged 1 commit intoapache:mainfrom
kevinjqliu:kevinjqliu/zizmor-dependabot

Conversation

@kevinjqliu
Copy link
Copy Markdown
Contributor

zizmor covers dependabot too (uvx zizmor --offline .github/)
It recommends adding 7 day cooldown period, https://docs.zizmor.sh/audits/#dependabot-cooldown

@kevinjqliu kevinjqliu changed the title add cooldown to dependabot ci: add cooldown to dependabot Mar 27, 2026
@github-actions github-actions bot added the INFRA label Mar 27, 2026
@kevinjqliu kevinjqliu merged commit b9d9053 into apache:main Mar 27, 2026
34 checks passed
@kevinjqliu kevinjqliu deleted the kevinjqliu/zizmor-dependabot branch March 27, 2026 21:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants