Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot supports configuration of a minimum package age before creating a PR [GA] #1105

Open
glider-bot opened this issue Feb 20, 2025 · 0 comments
Labels
ga Feature phase: Generally available GHES 3.18 GHES 3.18 GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security

Comments

@glider-bot
Copy link
Collaborator

Value Prop

This feature allows Dependabot users to optionally configure a delay for opening a Dependabot PR for a newly updated dependency until a certain amount of time has passed.

Expected Outcome

The cooldown feature helps teams improve security and reduce noise from frequent dependency updates by delaying Dependabot PRs for a configurable period, allowing time for patch releases and stabilizing updates without disrupting project workflows.

@glider-bot glider-bot added ga Feature phase: Generally available GHES 3.18 GHES 3.18 GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security labels Feb 20, 2025
@glider-bot glider-bot moved this to Q1 2025 – Jan-Mar in GitHub Public Roadmap Feb 20, 2025
@github github locked and limited conversation to collaborators Feb 20, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
ga Feature phase: Generally available GHES 3.18 GHES 3.18 GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security
Projects
Status: Q1 2025 – Jan-Mar
Development

No branches or pull requests

1 participant