Skip to content

chore: Add Dependabot version-update cooldown#149

Open
ld-repository-standards[bot] wants to merge 1 commit into
mainfrom
ld-github-standards/add-dependabot-cooldown
Open

chore: Add Dependabot version-update cooldown#149
ld-repository-standards[bot] wants to merge 1 commit into
mainfrom
ld-github-standards/add-dependabot-cooldown

Conversation

@ld-repository-standards

@ld-repository-standards ld-repository-standards Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

This pull request was auto generated by the LaunchDarkly Github Standards automation platform.

  • Ensure every entry under updates in .github/dependabot.yml declares a cooldown of at least 7 days (default-days).
  • Add entries for detected package ecosystems that were not yet tracked by Dependabot.

Cooldown applies only to version updates; security updates bypass it, so critical CVE fixes are never delayed.

Ref: SEC-8058.


Note

Low Risk
Only adds dependency automation config; no application, auth, or runtime code changes.

Overview
Introduces .github/dependabot.yml so Dependabot tracks GitHub Actions and npm at the repo root on a weekly schedule.

Each ecosystem sets cooldown.default-days: 7, spacing routine version-update PRs per org standards (SEC-8058). Security updates are not subject to this cooldown, so urgent dependency fixes can still land immediately.

Reviewed by Cursor Bugbot for commit 46e59b9. Bugbot is set up for automated code reviews on this repo. Configure here.

@ld-repository-standards ld-repository-standards Bot requested a review from a team June 17, 2026 06:45
@ld-repository-standards ld-repository-standards Bot requested a review from a team as a code owner June 17, 2026 06:45
@ld-repository-standards ld-repository-standards Bot requested a review from a team June 17, 2026 06:45
@keelerm84 keelerm84 removed the request for review from a team June 17, 2026 20:44

@joker23 joker23 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Need to reassess.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant