← Back

Wire · technology

Dependabot version updates introduce default package cooldown

Published

15 July 2026

Topic

technology

Sectors

Developer ToolsData Infrastructure

Geography

United States

Source

Read at github.blog

Verified

Fusion42 · 15 July 2026 · Fusion42 review

GitHub's Dependabot now defaults to a three-day cooldown before opening version update pull requests, reducing exposure to compromised or broken releases whilst security updates remain immediate. The change applies across all ecosystems and is configurable per project.

This Wire brief sits within Fusion42's coverage of Developer Tools and Data Infrastructure.

◆ The Wire takeaway

If you're shipping code that depends on npm, PyPI or other registries, your dependency updates just got slower by default—but your supply chain got safer. You now have three days to spot a poisoned release before it lands in your repo, and you can tighten or loosen that window in one line of config.

Coverage

1 source · 15 Jul 2026

Related on Wire

Topics

Developer ToolsData Infrastructuredependabotsupply-chaindependency-managementsecurity-defaultsopen-source