Skip to content

Commit 58fdede

Browse files
committed
Let Dependabot propose a release only once it is a week old
zizmor (dependabot-cooldown) flagged both update entries in dependabot.yml: without a cooldown, Dependabot waits only its implicit three days before it proposes a new version of an action or a Gradle dependency. A compromised or broken release is usually pulled within days, and the auto-merge workflow approves minor and patch updates on its own, so both entries now wait seven days. The cooldown applies to version updates only; security updates are not delayed.
1 parent 71c8c57 commit 58fdede

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

‎.github/dependabot.yml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,19 @@
11
version: 2
2+
# A release is proposed only once it is a week old: a compromised or broken release is usually pulled
3+
# within days. The cooldown holds back version updates only; security updates still come at once.
24
updates:
35
- package-ecosystem: "github-actions"
46
directory: "/"
57
schedule:
68
interval: "weekly"
79
target-branch: "main"
10+
cooldown:
11+
default-days: 7
812

913
- package-ecosystem: "gradle"
1014
directory: "/"
1115
schedule:
1216
interval: "weekly"
1317
target-branch: "main"
18+
cooldown:
19+
default-days: 7

0 commit comments

Comments
 (0)