Wire · technology
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 27 July 2026 · Fusion42 review
GitHub has implemented a mandatory 3-day cooldown in Dependabot before version updates are applied automatically, whilst security patches are still issued immediately. The change aims to reduce the window for poisoned package attacks to propagate, balancing supply-chain safety against dependency freshness.
This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity, and 7 sources have reported it between 27 Jul 2026 and 31 Jul 2026.
◆ ◆ The Wire takeaway
If you build dependency-automation or package-security tooling, Dependabot just made a 3-day lag the default behaviour—that's real friction you can now sell around. Enterprises wanting faster updates or tighter control now have a reason to layer your tool on top of GitHub's.
◆ Coverage
7 sources · first reported 27 Jul 2026 · latest 31 Jul 2026
◆ Related on Wire
◆ Topics