-
-
Notifications
You must be signed in to change notification settings - Fork 33.6k
Add a cooldown period to dependabot #141866
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We already have a monthly interval, so E[dependency updated] is a fortnight. As such I think 14 days might be overkill?
A
|
The monthly schedule is not a cooldown. A security cooldown means not auto-updating to a dep until that long after it's release. |
|
fixed up. i'm leaving it as 14d because with our existing monthly schedule we're already not trying to get new versions fast anyways. whenever there is an actual urgent need we'll already be making our own PR, so i'm opting to move slower by default. |
The rational of this practice is well laid out in https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns.