Skip to content

[codex] Apply a Dependabot cooldown of 7 days#21599

Merged
ww-oai merged 1 commit intomainfrom
ww/cooldown
May 7, 2026
Merged

[codex] Apply a Dependabot cooldown of 7 days#21599
ww-oai merged 1 commit intomainfrom
ww/cooldown

Conversation

@ww-oai
Copy link
Copy Markdown
Contributor

@ww-oai ww-oai commented May 7, 2026

This adds 7-day cooldowns to all of our Dependabot ecosystem blocks. Our Dependabot runs will continue at the same cadence as before, but the scheduled PRs will no suggest updates that are fewer than 7 days old themselves. This serves two purposes: to let dependencies "bake" for a bit in terms of stability before we adopt them, and to give third-party security services/tooling a chance to detect and revoke malware.

This should have no functional changes/consequences besides how rapidly we get (non-security) updates. Dependabot security PRs can still be scheduled and will bypass the cooldown.

@ww-oai ww-oai self-assigned this May 7, 2026
Copy link
Copy Markdown
Collaborator

@bolinfest bolinfest left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@ww-oai ww-oai merged commit 893038f into main May 7, 2026
26 checks passed
@ww-oai ww-oai deleted the ww/cooldown branch May 7, 2026 23:07
@github-actions github-actions Bot locked and limited conversation to collaborators May 7, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants