Skip to content

chore: add 7-day package cooldowns (Dependabot)#93

Merged
audunru merged 1 commit into
mainfrom
chore/cooldown
May 14, 2026
Merged

chore: add 7-day package cooldowns (Dependabot)#93
audunru merged 1 commit into
mainfrom
chore/cooldown

Conversation

@audunru
Copy link
Copy Markdown
Owner

@audunru audunru commented May 14, 2026

Summary

  • Adds `cooldown` blocks to all Dependabot update entries — prevents PRs for packages published in the last 7 days
  • Security updates are automatically exempt from the Dependabot cooldown

Why

Reduces exposure to supply-chain attacks on freshly released package versions.
See https://cooldowns.dev for background.

@audunru audunru merged commit 31a3c8a into main May 14, 2026
2 checks passed
@audunru audunru deleted the chore/cooldown branch May 14, 2026 08:18
@audunru
Copy link
Copy Markdown
Owner Author

audunru commented May 25, 2026

🎉 This PR is included in version 4.1.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant