Skip to content

Added a cooldown to dep bot updates#23220

Merged
sureshjoshi merged 1 commit intopantsbuild:mainfrom
sureshjoshi:depbot-cooldown
Apr 6, 2026
Merged

Added a cooldown to dep bot updates#23220
sureshjoshi merged 1 commit intopantsbuild:mainfrom
sureshjoshi:depbot-cooldown

Conversation

@sureshjoshi
Copy link
Copy Markdown
Member

@sureshjoshi sureshjoshi added category:internal CI, fixes for not-yet-released features, etc. release-notes:not-required [CI] PR doesn't require mention in release notes labels Apr 6, 2026
Copy link
Copy Markdown
Contributor

@cburroughs cburroughs left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

7 seems like a reasonable lucky number to try.

Were you motivated by security or "noise"?

@sureshjoshi
Copy link
Copy Markdown
Member Author

7 seems like a reasonable lucky number to try.

Were you motivated by security or "noise"?

7 is the default, just surfacing it. In watching all the hell that goes down in the JS supply-chain world, most of these sorts of issues are captured within the first few hours to maybe a day or two - or basically "never". I've been using this since it came out in PNPM.

Definitely motivated by security. I'm still working through my local dev machine security to mitigate issues, but stuff like this is better for the community - especially as cargo, left unchecked, basically just yolos updates.

Apparently this option has been here for a while, but I either didn't grok what it did, or didn't clue in that it existed. Had my brain been working, it would have been on at the start.

I was reviewing some Rust updates, and saw a commit in one of our deps that added it, which referenced zizmor - who has a rule for it. So just 100% oversight on my part.

@sureshjoshi sureshjoshi merged commit 542ca04 into pantsbuild:main Apr 6, 2026
25 checks passed
@sureshjoshi sureshjoshi deleted the depbot-cooldown branch April 6, 2026 18:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

category:internal CI, fixes for not-yet-released features, etc. release-notes:not-required [CI] PR doesn't require mention in release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants