Wire · technology
Dependabot version updates introduce default package cooldown
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 15 July 2026 · Fusion42 review
GitHub's Dependabot now defaults to a three-day cooldown before opening version update pull requests, reducing exposure to compromised or broken releases whilst security updates remain immediate. The change applies across all ecosystems and is configurable per project.
This Wire brief sits within Fusion42's coverage of Developer Tools and Data Infrastructure.
◆ ◆ The Wire takeaway
If you're shipping code that depends on npm, PyPI or other registries, your dependency updates just got slower by default—but your supply chain got safer. You now have three days to spot a poisoned release before it lands in your repo, and you can tighten or loosen that window in one line of config.
◆ Coverage
1 source · 15 Jul 2026
◆ Related on Wire
◆ Topics