GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request.

“The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project,” the Microsoft-owned subsidiary said.

According to GitHub, the

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Cloud in a Bottle: making self-hosting accessible to everyone

Cloud in a Bottle: making self-hosting accessible to everyone Source: Hacker News

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet

Ponytail: Lazy Senior Engineer Skill

Ponytail: Lazy Senior Engineer Skill Source: Hacker News