Skip to content

Add Dependabot version-update cooldown#712

Open
ld-repository-standards[bot] wants to merge 1 commit into
mainfrom
ld-github-standards/add-dependabot-cooldown
Open

Add Dependabot version-update cooldown#712
ld-repository-standards[bot] wants to merge 1 commit into
mainfrom
ld-github-standards/add-dependabot-cooldown

Conversation

@ld-repository-standards

@ld-repository-standards ld-repository-standards Bot commented Jun 11, 2026

Copy link
Copy Markdown

This pull request was auto generated by the LaunchDarkly Github Standards automation platform.

  • Ensure every entry under updates in .github/dependabot.yml declares a cooldown of at least 7 days (default-days).
  • Add entries for detected package ecosystems that were not yet tracked by Dependabot.

Cooldown applies only to version updates; security updates bypass it, so critical CVE fixes are never delayed.

Ref: SEC-8058.


Note

Low Risk
CI/dependency automation only; no application runtime or security logic changes.

Overview
Updates .github/dependabot.yml so every updates entry uses a 7-day version-update cooldown (cooldown.default-days: 7), including the existing gomod job at repo root.

Adds weekly Dependabot tracking for docker, github-actions, and npm at /, plus a second npm entry for /internal/dev_server/ui. Per the PR description, cooldown affects routine version bumps only; security updates are not delayed.

Reviewed by Cursor Bugbot for commit f9d882f. Bugbot is set up for automated code reviews on this repo. Configure here.

@ld-repository-standards ld-repository-standards Bot requested review from a team June 11, 2026 01:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants