Published July 23, 2026 ยท Added July 25, 2026

The case for a cooldown: Why Dependabot now waits before issuing version updates

GitHub says Dependabot version updates now default to a three-day cooldown, giving maintainers and security researchers time to detect malicious releases and publish fixes before automation spreads new package versions through downstream projects.

GitHub says Dependabot version updates now default to a three-day cooldown, giving maintainers and security researchers time to detect malicious releases and publish fixes before automation spreads new package versions through downstream projects.

Read the original story.

Source: GitHub Blog