logo

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

ID: 64850600-fd33-57f1-a01f-aab0ba5734d0

STIX ID: report--64850600-fd33-57f1-a01f-aab0ba5734d0

Feed Name: The Hacker News

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: [email protected] (The Hacker News)

...
...

GitHub introduced a default three-day cooldown for Dependabot version-update pull requests to reduce the window in which recently published, potentially poisoned packages can spread to downstream projects; security patches remain immediate and the cooldown is configurable. The article frames this as one defensive layer alongside measures such as lockfile pinning, disabling install scripts in CI, scoping pipeline tokens, and manual review, and notes similar time-based controls being adopted across package ecosystems and PyPI's plan to block file additions after 14 days.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.