Skip to content

[DEV-74] chore: add 30-day dependabot cooldown#202

Open
austinpray-mixpanel wants to merge 1 commit intomasterfrom
dependabot-cooldown
Open

[DEV-74] chore: add 30-day dependabot cooldown#202
austinpray-mixpanel wants to merge 1 commit intomasterfrom
dependabot-cooldown

Conversation

@austinpray-mixpanel
Copy link
Copy Markdown
Member

@austinpray-mixpanel austinpray-mixpanel commented Mar 24, 2026

Bootstraps dependabot with cooldown.default-days: 30 on all ecosystems. This delays PRs until a new dependency version has been stable for 30 days, reducing supply-chain risk from fast-moving malicious releases.

Linear: https://linear.app/mixpanel/issue/DEV-74/ensure-all-repos-have-dependabotyml-with-30-day-cooldown

@austinpray-mixpanel austinpray-mixpanel requested review from a team, andyleap and gmasnica and removed request for a team March 24, 2026 15:26
@austinpray-mixpanel austinpray-mixpanel changed the title chore: add 30-day dependabot cooldown [DEV-74] chore: add 30-day dependabot cooldown Mar 24, 2026
@linear
Copy link
Copy Markdown

linear bot commented Mar 24, 2026

@austinpray-mixpanel austinpray-mixpanel requested a review from a team March 24, 2026 21:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants