Skip to content

Conversation

@jspeed-meyers
Copy link
Collaborator

I suggest adding a cooldown period to the dependabot updates. See this blog post for why: https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns

@bact
Copy link
Collaborator

bact commented Nov 22, 2025

Agreed on this. Good to know about the feature.

@bact bact added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Nov 22, 2025
@bact bact merged commit b5da231 into main Nov 22, 2025
18 checks passed
@goneall
Copy link
Member

goneall commented Nov 22, 2025

Looks like something we could add to some of the other SPDX repos

@jspeed-meyers jspeed-meyers deleted the add-cooldown-period branch November 23, 2025 00:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants