Skip to content

Conversation

@rmuir
Copy link
Member

@rmuir rmuir commented Oct 26, 2025

Addresses the new zizmor alerts around this issue.

Waits a configurable number of days for a dependency to be released, before creating a pull request for it. This is helpful when there are supply chain security issues such as the recent NPM incidents.

https://docs.zizmor.sh/audits/#dependabot-cooldown

Addresses the new zizmor alerts around this issue.

Waits a configurable number of days for a dependency to be released,
before creating a pull request for it. This is helpful when there are
supply chain security issues such as the recent NPM incidents.

https://docs.zizmor.sh/audits/#dependabot-cooldown
@github-actions
Copy link
Contributor

This PR does not have an entry in lucene/CHANGES.txt. Consider adding one. If the PR doesn't need a changelog entry, then add the skip-changelog label to it and you will stop receiving this reminder on future updates to the PR.

@dweiss dweiss added this to the 11.0.0 milestone Oct 26, 2025
@rmuir rmuir merged commit 63d6571 into apache:main Oct 26, 2025
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants