A new three-day cooldown in Dependabot changes automated updates from instant reaction to release-age vetting, aiming to blunt fast-moving supply chain abuse.
A new default cooldown for Dependabot version updates is designed to slow the automatic adoption of newly released packages and narrow the window for supply-chain abuse.
A default three-day cooldown for version updates changes how quickly automation can promote newly published dependencies into a maintainer’s review queue.
A new default cooldown in Dependabot shows how open-source defenders are using age, not just signatures, to slow risky dependency updates.