Skip to content

Conversation

@dguido
Copy link
Member

@dguido dguido commented Dec 15, 2025

Summary

  • Add 7-day cooldown to protect against supply chain attacks
  • Group updates by ecosystem to reduce PR noise
  • Change schedule from daily to weekly
  • Add Docker ecosystem for base image updates

A 7-day cooldown blocks ~80% of supply chain attacks by giving time for malicious packages to be detected and removed before they're automatically merged.

Test plan

  • Verify YAML syntax is valid
  • Confirm Dependabot picks up the new config after merge

🤖 Generated with Claude Code

- Add 7-day cooldown to protect against supply chain attacks
- Group updates by ecosystem to reduce PR noise
- Change schedule from daily to weekly
- Add Docker ecosystem for base image updates

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@dguido dguido requested a review from jackivanov as a code owner December 15, 2025 00:54
@dguido dguido merged commit 0d314ea into master Dec 15, 2025
22 of 23 checks passed
@dguido dguido deleted the dependabot-cooldown-config branch December 15, 2025 00:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants