Skip to content

Conversation

@pcarleton
Copy link
Member

Summary

  • Adds Dependabot configuration with 7-day cooldown for both npm and github-actions ecosystems
  • Dependency cooldowns delay automatic updates until packages have been published for a set period, protecting against supply chain attacks

Background

According to this analysis, 8 out of 10 recent supply chain attacks had exploitation windows under one week. A 7-day cooldown would have prevented the vast majority of these attacks from reaching end users.

Test plan

  • Dependabot config is valid YAML
  • Verify Dependabot picks up the config after merge

🤖 Generated with Claude Code

Configures Dependabot to wait 7 days after a package is published
before creating update PRs. This helps protect against supply chain
attacks by allowing time for malicious packages to be detected and
removed.

See: https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
@pkg-pr-new
Copy link

pkg-pr-new bot commented Nov 25, 2025

Open in StackBlitz

npx https://pkg.pr.new/modelcontextprotocol/conformance/@modelcontextprotocol/conformance@57

commit: de6d9f7

@pcarleton pcarleton merged commit 6464588 into main Nov 25, 2025
8 checks passed
@pcarleton pcarleton deleted the dependabot-cooldown branch November 25, 2025 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants