Skip to content

Conversation

@gpshead
Copy link
Member

@gpshead gpshead commented Nov 23, 2025

Copy link
Member

@AA-Turner AA-Turner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We already have a monthly interval, so E[dependency updated] is a fortnight. As such I think 14 days might be overkill?

A

@AA-Turner AA-Turner added the type-security A security issue label Nov 23, 2025
@AA-Turner AA-Turner changed the title [security] Add a cooldown period to dependabot Add a cooldown period to dependabot Nov 23, 2025
@gpshead
Copy link
Member Author

gpshead commented Nov 23, 2025

The monthly schedule is not a cooldown. A security cooldown means not auto-updating to a dep until that long after it's release.

@gpshead
Copy link
Member Author

gpshead commented Nov 23, 2025

fixed up. i'm leaving it as 14d because with our existing monthly schedule we're already not trying to get new versions fast anyways. whenever there is an actual urgent need we'll already be making our own PR, so i'm opting to move slower by default.

@gpshead gpshead merged commit 2746c69 into python:main Nov 23, 2025
46 checks passed
@gpshead gpshead deleted the dependabot-cooldowns branch November 23, 2025 09:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants