At a glance: Dependabot will now wait three days by default after a new package release before automatically creating pull requests — the cooldown is configurable in dependabot.yml.
GitHub is integrating a new cooldown mechanism into Dependabot that delays update processes by at least three days after package publication. The goal is to reduce the adoption of manipulated dependencies.
GitHub has announced a new cooldown feature in Dependabot. This delays the automatic creation of pull requests by at least three days after the release of a new package version.
The procedure aims to reduce development teams’ vulnerability to so-called supply-chain attacks. In particular, newly published packages are a known attack window: if attackers gain control of a popular project or register a new package with a similar name, they can inject poisoned versions in a timely manner. Immediate adoption by automated tools increases the risk.
Configuration remains flexible: the cooldown setting in the dependabot.yml file allows teams to adjust the waiting period to their own requirements or establish a different strategy. This enables teams to balance security and speed, depending on the criticality of their dependencies.
Source: thehackernews.com · Published 27 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.