Skip to content

Update GitHub config#48

Merged
simonwhatley merged 2 commits intomainfrom
update-dependabot
Apr 27, 2026
Merged

Update GitHub config#48
simonwhatley merged 2 commits intomainfrom
update-dependabot

Conversation

@simonwhatley
Copy link
Copy Markdown
Collaborator

This PR updates the GitHub config:

  • added cooldown params to dependabot.yml - This feature mitigates supply chain risks by letting new packages "cool down" while security vendors identify malicious updates, preventing developer alert fatigue from frequent updates.
  • added an auto-merge workflow that minor and patch releases for dependencies are auto-merged by GitHub.

@simonwhatley simonwhatley merged commit 820630e into main Apr 27, 2026
@simonwhatley simonwhatley deleted the update-dependabot branch April 27, 2026 10:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant