LOWVulnerability
Global

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

·Source: The Hacker News

Updated:

Executive Summary

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project," the Microsoft-owned subsidiary said. According to GitHub, the

Analysis

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project," the Microsoft-owned subsidiary said. According to GitHub, the
Source Attribution

Originally published by The Hacker News on Jul 27, 2026.

Related Threats