Commit de6d9f7
Add dependabot config with 7-day dependency cooldown
Configures Dependabot to wait 7 days after a package is published
before creating update PRs. This helps protect against supply chain
attacks by allowing time for malicious packages to be detected and
removed.
See: https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>1 parent b96a29a commit de6d9f7
1 file changed
+16
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
0 commit comments