← Back

Wire · technology

GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies

Published

27 July 2026

Topic

technology

Sectors

Developer ToolsCybersecurity

Geography

United States

Source

Read at gbhackers.com

Verified

Fusion42 · 27 July 2026 · Fusion42 review

GitHub has implemented a default 333-day cooldown period for Dependabot routine version updates to prevent automated adoption of poisoned open-source packages before malicious code can be detected, whilst keeping security updates immediate.

This Wire brief sits within Fusion42's coverage of Developer Tools and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

If you're selling dependency management, vulnerability scanning, or supply-chain monitoring to dev teams, your pitch just got easier—GitHub just admitted their default automation is a liability, and teams now need more than one layer of protection. The market for 'what happens between patch release and human review' just opened.

Related on Wire

Topics

Developer ToolsCybersecuritydependabotsupply-chain-securityopen-source-riskmalware-detectionautomation-risk