Skip to content

✨ Add cooldown to Dependabot updates#6332

Merged
chris-rock merged 1 commit intomainfrom
czunker/dependabot_cooldown
Dec 22, 2025
Merged

✨ Add cooldown to Dependabot updates#6332
chris-rock merged 1 commit intomainfrom
czunker/dependabot_cooldown

Conversation

@czunker
Copy link
Copy Markdown
Contributor

@czunker czunker commented Dec 22, 2025

One of the learnings from the latest supply chain attacks is, that parts of it can be mitigated by not updating asap.

This adds a cooldown settings to our Depndabot updates.

One of the learnings from the latest supply chain attacks is, that parts of it can be mitigated by not updating asap.

This adds a cooldown settings to our Depndabot updates.

Signed-off-by: Christian Zunker <christian@mondoo.com>
@czunker czunker marked this pull request as ready for review December 22, 2025 15:24
@chris-rock chris-rock merged commit 280f657 into main Dec 22, 2025
9 checks passed
@chris-rock chris-rock deleted the czunker/dependabot_cooldown branch December 22, 2025 15:26
@github-actions github-actions bot locked and limited conversation to collaborators Dec 22, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants