Skip to content

Conversation

@p-r-a-v-i-n
Copy link

from docs :

Detects missing or insufficient cooldown settings in Dependabot configuration files.
By default, Dependabot does not perform any "cooldown" on dependency updates. In other words, a regularly scheduled Dependabot run may perform an update on a dependency that was just released moments before the run began. This presents both stability and supply-chain security risks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant