← Back

Wire · technology

GitHub now includes a '3-day wait' as standard for automatic dependency updates to ...

Published

15 July 2026

Topic

technology

Sectors

Developer ToolsCybersecurity

Geography

United States

Source

Read at gigazine.net

Verified

Fusion42 · 15 July 2026 · Fusion42 review

GitHub has made a 3-day cooldown the default setting for Dependabot version updates, delaying automatic dependency pulls to reduce exposure to malicious or buggy package releases. Security patches bypass the delay and pull immediately.

This Wire brief sits within Fusion42's coverage of Developer Tools and Cybersecurity.

◆ The Wire takeaway

If you ship code that auto-updates dependencies without review, your CI/CD pipeline just got slower by default—but that's now the baseline for your competitors too, so your customers expect it. The real move: security patches still run instantly, so you now have a window to build tooling that spots the difference between a genuine fix and a trojanised release.

Coverage

1 source · 15 Jul 2026

Related on Wire

Topics

Developer ToolsCybersecuritydependency-managementsupply-chain-securityopen-sourcedevopsmalicious-packages