HackerFeeds

CyberSecurity News

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

The Hacker News
· July 27, 2026

AI summary

GitHub has introduced a 3-day cooldown period in Dependabot to delay the adoption of newly released packages. This mechanism allows Dependabot to wait at least three days after a release is published before opening a pull request. The cooldown period is configurable through the dependabot.yml file, enabling users to choose a different cooldown setting that suits their project needs. This change aims to limit the potential impact of poisoned packages. GitHub made this announcement to inform users about the new cooldown mechanism in Dependabot. The configuration option provides flexibility for users to adjust the cooldown period according to their project requirements.

Read the full article at The Hacker Newsthehackernews.com/2026/07/github-adds-3-day-dependabot-cooldown.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.