- Sources: GitHub Changelog, HN 48913050
- Summary: GitHub announced on 2026-07-14 that Dependabot version updates now apply a default package cooldown, a waiting period after a release before Dependabot opens the update pull request. The default applies only to version updates. Security updates still open immediately, so patches for known vulnerabilities are not delayed. The cooldown is configurable in the Dependabot configuration.
- Comments: HN commenters describe the change as trading a short exposure to a freshly published malicious release for a slightly longer window on unpatched non-security bugs, and note it depends on third-party scanners catching a bad package during the cooldown rather than on users hitting it in production.
- Why it matters: It changes the default supply-chain posture for every repository that relies on Dependabot version updates, favoring a delay that lets a compromised release be caught before it is auto-proposed.
send feedback on this story