Skip to content

ci: add 7-day Dependabot cooldown to reduce supply-chain risk#54

Merged
edmondas merged 1 commit into
mainfrom
chore/dependabot-cooldown
May 31, 2026
Merged

ci: add 7-day Dependabot cooldown to reduce supply-chain risk#54
edmondas merged 1 commit into
mainfrom
chore/dependabot-cooldown

Conversation

@edmondas
Copy link
Copy Markdown
Member

Adds a 7-day cooldown to all three Dependabot ecosystems (gomod, github-actions, docker).

Dependabot now waits until a release has been publicly available for 7 days before opening a PR, reducing exposure to compromised or yanked supply-chain releases that get pulled shortly after publication.

@edmondas edmondas merged commit 64eb383 into main May 31, 2026
11 checks passed
@edmondas edmondas deleted the chore/dependabot-cooldown branch May 31, 2026 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant