Skip to content

Commit 557e22c

Browse files
fix: add Dependabot cooldown (7-day) for supply-chain protection (#155)
Adds `cooldown.default-days: 7` to all 4 ecosystem entries. This delays auto-ingesting newly-published versions, protecting against short-lived supply-chain compromises that are typically yanked within hours. Security updates are unaffected — they bypass cooldown entirely. Fixes #154 Co-authored-by: bgagent <345885+scottschreckengaust@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent 98aff27 commit 557e22c

1 file changed

Lines changed: 8 additions & 0 deletions

File tree

.github/dependabot.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@ updates:
66
schedule:
77
interval: "weekly"
88
day: "saturday"
9+
cooldown:
10+
default-days: 7
911
commit-message:
1012
prefix: "chore(deps): actions"
1113
open-pull-requests-limit: 1
@@ -19,6 +21,8 @@ updates:
1921
schedule:
2022
interval: "weekly"
2123
day: "saturday"
24+
cooldown:
25+
default-days: 7
2226
commit-message:
2327
prefix: "chore(deps): docker"
2428
open-pull-requests-limit: 1
@@ -32,6 +36,8 @@ updates:
3236
schedule:
3337
interval: "weekly"
3438
day: "saturday"
39+
cooldown:
40+
default-days: 7
3541
commit-message:
3642
prefix: "chore(deps): uv"
3743
open-pull-requests-limit: 1
@@ -45,6 +51,8 @@ updates:
4551
schedule:
4652
interval: "weekly"
4753
day: "saturday"
54+
cooldown:
55+
default-days: 7
4856
commit-message:
4957
prefix: "chore(deps): npm"
5058
open-pull-requests-limit: 1

0 commit comments

Comments
 (0)