-
-
Notifications
You must be signed in to change notification settings - Fork 6.5k
ci: set 3-day cooldown for Dependabot updates #8016
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎ 1 Skipped Deployment
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
This PR adds a 3-day cooldown period for Dependabot updates to improve security by delaying dependency updates until they've been published for at least three days, allowing time to identify and resolve potential compromises.
- Adds
cooldownconfiguration withdefault-days: 3to both GitHub Actions and npm package ecosystems - Enhances security posture by preventing immediate adoption of potentially compromised dependency versions
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8016 +/- ##
==========================================
- Coverage 73.01% 73.00% -0.02%
==========================================
Files 95 95
Lines 8317 8317
Branches 214 214
==========================================
- Hits 6073 6072 -1
- Misses 2243 2244 +1
Partials 1 1 ☔ View full report in Codecov by Sentry. |
AugustinMauroy
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGMT ! I never heard about that but it's super cool
Description
Reduces the risk from compromised dependency versions by requiring that they've been published for at least three days before Dependabot will update us to them, giving time for maintainers and the community to spot and resolve compromises.
Validation
https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference#cooldown-
Related Issues
nodejs/web-team#25
Check List
pnpm formatto ensure the code follows the style guide.pnpm testto check if all tests are passing.pnpm buildto check if the website builds without errors.