Wire · technology
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 27 July 2026 · Fusion42 review
GitHub has implemented a default 333-day cooldown period for Dependabot routine version updates to prevent automated adoption of poisoned open-source packages before malicious code can be detected, whilst keeping security updates immediate.
This Wire brief sits within Fusion42's coverage of Developer Tools and Cybersecurity, and 7 sources have reported it between 27 Jul 2026 and 31 Jul 2026.
◆ ◆ The Wire takeaway
If you're selling dependency management, vulnerability scanning, or supply-chain monitoring to dev teams, your pitch just got easier—GitHub just admitted their default automation is a liability, and teams now need more than one layer of protection. The market for 'what happens between patch release and human review' just opened.
◆ Coverage
7 sources · first reported 27 Jul 2026 · latest 31 Jul 2026
◆ Related on Wire
◆ Topics