← Back

Wire · technology

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

Published

27 July 2026

Topic

technology

Sectors

Enterprise SoftwareCybersecurity

Geography

United States

Source

Read at thehackernews.com

Verified

Fusion42 · 27 July 2026 · Fusion42 review

GitHub has implemented a mandatory 3-day cooldown in Dependabot before version updates are applied automatically, whilst security patches are still issued immediately. The change aims to reduce the window for poisoned package attacks to propagate, balancing supply-chain safety against dependency freshness.

This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

If you build dependency-automation or package-security tooling, Dependabot just made a 3-day lag the default behaviour—that's real friction you can now sell around. Enterprises wanting faster updates or tighter control now have a reason to layer your tool on top of GitHub's.

Related on Wire

Topics

Enterprise SoftwareCybersecuritydependency-managementsupply-chain-securitydevops-toolingmalicious-packagesautomation-risk