Skip to content

chore: add 7-day cooldown for dependabot updates#791

Merged
thomaswhyyou merged 1 commit into
mainfrom
dependabot-min-package-age
May 19, 2026
Merged

chore: add 7-day cooldown for dependabot updates#791
thomaswhyyou merged 1 commit into
mainfrom
dependabot-min-package-age

Conversation

@thomaswhyyou
Copy link
Copy Markdown
Contributor

@thomaswhyyou thomaswhyyou commented May 19, 2026

Summary

  • Adds cooldown.default-days: 7 to the npm dependabot config, mirroring knocklabs/control#8356.
  • Excludes @knocklabs/* and @telegraph/* so internal packages still flow through without delay.
  • Reduces churn from day-zero version bumps and gives upstream regressions a week to surface before we open PRs.

Mirrors the policy from knocklabs/control#8356 to reduce churn from
day-zero dependency PRs while still letting internal @knocklabs and
@telegraph packages flow through immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@linear-code
Copy link
Copy Markdown

linear-code Bot commented May 19, 2026

KNO-13221

@thomaswhyyou thomaswhyyou merged commit 1d44d15 into main May 19, 2026
8 checks passed
@thomaswhyyou thomaswhyyou deleted the dependabot-min-package-age branch May 19, 2026 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants