The case for a cooldown: Why Dependabot now waits before issuing version updates
CYBERSECURITY FEATURED ANALYSIS

The case for a cooldown: Why Dependabot now waits before issuing version updates

BY

Carlin Cherry

SOURCE

The latest security news for developers - The GitHub Blog

DATE

READ

1 min read

A new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code. The post The case for a cooldown: Why …

A new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code. The post The case for a cooldown: Why Dependabot now waits before issuing version updates appeared first on The GitHub Blog.