Skip to content

chore: add Dependabot cooldown — Python (pip)#8

Merged
andrei-ifrim merged 2 commits into
mainfrom
chore/dependabot-cooldown-adr-011
May 27, 2026
Merged

chore: add Dependabot cooldown — Python (pip)#8
andrei-ifrim merged 2 commits into
mainfrom
chore/dependabot-cooldown-adr-011

Conversation

@andrei-ifrim

Copy link
Copy Markdown
Contributor

https://www.notion.so/ADR-011-Introduce-Cooldown-Period-for-Dependency-Updates-2e37256fbc328194b407d081692279d5
https://www.notion.so/Safe-deployment-guardrails-for-SDLC-controls-rollout-3507256fbc3280368c22fc45fe65b8dd

Adds a 3-day cooldown to Dependabot dependency updates for Python (pip), as required by ADR-011.

The cooldown delays Dependabot PR creation by 3 days after a new package version is published. This provides a buffer to detect supply chain attacks or compromised releases before the organisation automatically adopts them.

Changes made:

  • Python (pip): added cooldown: default-days: 3

No other changes. All existing configuration — ignore rules, groups, registry settings, schedules, and PR limits — is untouched.

Risk classification: LOW — no workflows directory

@adrian-marza-oaknorth adrian-marza-oaknorth left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved: dependabot.yml cooldown config is syntactically correct (ADR-011). No CI pipeline will trigger post-merge.

@andrei-ifrim andrei-ifrim merged commit 41e83f7 into main May 27, 2026
1 check passed
@andrei-ifrim andrei-ifrim deleted the chore/dependabot-cooldown-adr-011 branch May 27, 2026 10:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants