Skip to content

Conversation

@oschwald
Copy link
Member

This PR sets the Dependabot cooldown period to 4 days for all package ecosystems.

Context

This addresses zizmor findings that flag missing or insufficient cooldown configuration in dependabot.yml files. The zizmor security tool requires a minimum cooldown of 4 days to avoid potential security issues with rapid dependency updates.

Changes

  • Added/updated cooldown configuration with default-days: 4 for all package ecosystems in .github/dependabot.yml

References

@github-actions
Copy link

github-actions bot commented Oct 30, 2025

Modver result

This report was generated by Modver,
a Go package and command that helps you obey semantic versioning rules in your Go module.

This PR does not require a change in your module’s version number.
(You might still consider bumping the patchlevel anyway.)

This addresses the zizmor findings by setting a cooldown period of 4 days
for all package ecosystems in dependabot.yml.

Related to: ENG-3236
@mm-kevcenteno mm-kevcenteno merged commit ab97eb3 into main Oct 31, 2025
18 of 20 checks passed
@mm-kevcenteno mm-kevcenteno deleted the greg/eng-3236 branch October 31, 2025 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants