Repository navigation
chore: group Dependabot security updates and add a 3-day cooldown - #120
Conversation
Security updates were the one Dependabot path with no groups, so an advisory burst opened one pull request per package. npm, uv and GitHub Actions now group them into one pull request per ecosystem. Every entry now also waits 3 days before proposing a new release. A hijacked version is usually pulled from the registry within that window. Cooldown never delays a security update. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Warning Review paused — included plan limit reachedKeep your review moving with free on-demand reviews.
On-demand reviews are free for the next 4 days.
Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing. Promotion and pricing detailsOn-demand reviews are free for the next 4 days. After that, they cost $0.25 per reviewed file. Review limit detailsOr wait 58 minutes for your next included review. Limit details: You’ve used all 2 included reviews currently available. Your 81 included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (1)
Comment |
There was a problem hiding this comment.
Blocking: 0 · Non-blocking: 0
The security groups target security updates separately from the existing version-update groups, and the cooldown is supported across the configured ecosystems without delaying security updates. Note: GitHub already applies a three-day default cooldown to version updates, so these entries make that policy explicit rather than changing the current delay.
Summary
cooldown. A new release has to be public for 3 days before Dependabot proposes it, so a hijacked version is usually pulled from the registry first. Cooldown never delays a security update.This matches the same change in opencodos/AITaaS#2910.
Verification
uvx check-jsonschema --builtin-schema vendor.dependabotpasses on the new file. A copy with typos in both new keys fails it, so the schema does check them.🤖 Generated with Claude Code