Skip to content

Conversation

steveoh
Copy link
Member

@steveoh steveoh commented Jul 30, 2025

This PR adds cooldown settings to the dependabot configuration for all package ecosystems.

What this does:

  • Allows dependabot to delay including dependencies for a configurable number of days
  • Excludes organization packages (ugrc-*, @ugrc/*, agrc/*) from cooldown delays so they update immediately

Benefits:

  • The community finds supply chain vulnerabilities and bugs before they are included in a pull request
  • Organization packages are updated immediately without delays for faster internal development cycles

@steveoh steveoh merged commit a958483 into main Jul 30, 2025
7 of 8 checks passed
@steveoh steveoh deleted the ci/cooldown-dependabot branch July 30, 2025 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant