Skip to content

[DEV-74] chore: add 30-day dependabot cooldown#2496

Open
austinpray-mixpanel wants to merge 1 commit intomainfrom
dependabot-cooldown
Open

[DEV-74] chore: add 30-day dependabot cooldown#2496
austinpray-mixpanel wants to merge 1 commit intomainfrom
dependabot-cooldown

Conversation

@austinpray-mixpanel
Copy link
Copy Markdown
Member

@austinpray-mixpanel austinpray-mixpanel commented Mar 24, 2026

Adds cooldown.default-days: 30 to all dependabot ecosystems. This delays PRs until a new dependency version has been stable for 30 days, reducing supply-chain risk from fast-moving malicious releases.

Also adds pip ecosystem tracking for utils/requirements.txt.

Linear: https://linear.app/mixpanel/issue/DEV-74/ensure-all-repos-have-dependabotyml-with-30-day-cooldown

@austinpray-mixpanel austinpray-mixpanel requested a review from a team as a code owner March 24, 2026 15:04
@austinpray-mixpanel austinpray-mixpanel requested review from santigracia and removed request for a team March 24, 2026 15:04
@vercel
Copy link
Copy Markdown

vercel bot commented Mar 24, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
docs Ready Ready Preview, Comment Mar 24, 2026 3:08pm

Request Review

@austinpray-mixpanel austinpray-mixpanel requested review from a team, gmasnica and marcusgreer and removed request for a team March 24, 2026 15:24
@austinpray-mixpanel austinpray-mixpanel changed the title chore: add 30-day dependabot cooldown [DEV-74] chore: add 30-day dependabot cooldown Mar 24, 2026
@linear
Copy link
Copy Markdown

linear bot commented Mar 24, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants