Skip to content

add 7 day cooldown to gradle package updates#1258

Merged
Jonopono123 merged 2 commits intomainfrom
NIAD-3448
Apr 15, 2026
Merged

add 7 day cooldown to gradle package updates#1258
Jonopono123 merged 2 commits intomainfrom
NIAD-3448

Conversation

@Jonopono123
Copy link
Copy Markdown
Contributor

What

Add default cooldown of 7 days to dependabot.yml for gradle packages.

Why

Following on from recent compromised package updates, we want to enforce a 7 day cooldown on any package updates to ensure that we're not potentially bringing dangerous updates into our deployments.

Type of change

Please delete options that are not relevant.

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Internal change (non-breaking change with no effect on the functionality affecting end users)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)

Checklist:

  • I have performed a self-review of my code
  • My changes generate no new warnings
  • New and existing unit tests pass locally with my changes

@Jonopono123 Jonopono123 requested a review from a team as a code owner April 14, 2026 14:23
@github-actions
Copy link
Copy Markdown

Looks good. No mutations were possible for these changes.
See https://pitest.org

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 14, 2026

Images built and published to ECR using a Build Id of PR-1014-20f9464

@Jonopono123 Jonopono123 merged commit 3b10ff0 into main Apr 15, 2026
30 of 31 checks passed
@Jonopono123 Jonopono123 deleted the NIAD-3448 branch April 15, 2026 10:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants