Skip to content

chore: Add Dependabot version-update cooldown - #53

Open
ld-repository-standards[bot] wants to merge 2 commits into
mainfrom
ld-github-standards/add-dependabot-cooldown
Open

chore: Add Dependabot version-update cooldown#53
ld-repository-standards[bot] wants to merge 2 commits into
mainfrom
ld-github-standards/add-dependabot-cooldown

Conversation

@ld-repository-standards

@ld-repository-standards ld-repository-standards Bot commented Jul 2, 2026

Copy link
Copy Markdown

This pull request was auto generated by the LaunchDarkly Github Standards automation platform.

  • Ensure every entry under updates in .github/dependabot.yml declares a cooldown of at least 7 days (default-days).
  • Add entries for detected package ecosystems that were not yet tracked by Dependabot.

Cooldown applies only to version updates; security updates bypass it, so critical CVE fixes are never delayed.

Ref: SEC-8058.


Note

Low Risk
Configuration-only change to Dependabot timing with no application runtime impact.

Overview
Adds a 7-day cooldown (default-days: 7) under the existing pip Dependabot update entry in .github/dependabot.yml, so routine version bumps are not opened immediately on top of a daily schedule.

This only affects version updates; Dependabot security updates are not subject to this cooldown.

Reviewed by Cursor Bugbot for commit c781b2e. Bugbot is set up for automated code reviews on this repo. Configure here.

@ld-repository-standards
ld-repository-standards Bot requested a review from a team July 2, 2026 06:12
@ld-repository-standards
ld-repository-standards Bot requested a review from a team as a code owner July 2, 2026 06:12
@ld-repository-standards
ld-repository-standards Bot requested a review from a team July 2, 2026 06:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants