Skip to content

Commit de6d9f7

Browse files
pcarletonclaude
andcommitted
Add dependabot config with 7-day dependency cooldown
Configures Dependabot to wait 7 days after a package is published before creating update PRs. This helps protect against supply chain attacks by allowing time for malicious packages to be detected and removed. See: https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
1 parent b96a29a commit de6d9f7

File tree

1 file changed

+16
-0
lines changed

1 file changed

+16
-0
lines changed

.github/dependabot.yml

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
version: 2
2+
3+
updates:
4+
- package-ecosystem: npm
5+
directory: /
6+
schedule:
7+
interval: weekly
8+
cooldown:
9+
default-days: 7
10+
11+
- package-ecosystem: github-actions
12+
directory: /
13+
schedule:
14+
interval: weekly
15+
cooldown:
16+
default-days: 7

0 commit comments

Comments
 (0)