GitHub introduced a 3-day cooldown on Dependabot non-security version update pull requests, providing vulnerability scanners a detection window to catch poisoned packages before automated merging.
Key Takeaways
- βCooldown applies exclusively to non-security bumps; critical security CVE patches trigger immediately;
- βGrants security scanners and community maintainers a 72-hour window to identify and revoke malicious releases;
- βGitHub Security published detailed supply-chain guidelines explaining the necessity of update buffers.
Discussion & Comments
0Sign in to join the discussion
Connect with AI developers to exchange benchmark insights.