Skip to content

chore: added 7 day cooldown to dependabot#206

Merged
samayer12 merged 1 commit intomainfrom
205-add-cooldown-to-dependabot
Feb 12, 2026
Merged

chore: added 7 day cooldown to dependabot#206
samayer12 merged 1 commit intomainfrom
205-add-cooldown-to-dependabot

Conversation

@AmberFryar
Copy link
Contributor

Added cooldown: default-days: 7 to all dependabot configurations. This will delay dependabot from opening a PR for dependency updates until they have matured 7 days. Most security patches will be released within days of a vulnerability being discovered on a new release. A 7 day cooldown will allow those patches to be applied before implementing.
Security patches are not affected by the cooldown. Dependabot will continue to open PRs immediately (unchanged workflow) for security patches.
Grouped dependencies PRs will open once all dependencies have individually cleared their cooldown period. This is expected behavior and may add a few extra days of delay for some updates, but keeps PR volume low. If a specific dependency frequently holds up a group, it can be pulled out into its own entry.

@AmberFryar AmberFryar requested a review from a team as a code owner February 11, 2026 22:52
@AmberFryar AmberFryar linked an issue Feb 11, 2026 that may be closed by this pull request
@netlify
Copy link

netlify bot commented Feb 11, 2026

Deploy Preview for pepr-docs ready!

Name Link
🔨 Latest commit ac3becd
🔍 Latest deploy log https://app.netlify.com/projects/pepr-docs/deploys/698d0845bda5f50008ee9486
😎 Deploy Preview https://deploy-preview-206--pepr-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 83 (🔴 down 12 from production)
Accessibility: 100 (no change from production)
Best Practices: 83 (no change from production)
SEO: 100 (no change from production)
PWA: -
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify project configuration.

@samayer12 samayer12 merged commit 2cd98fe into main Feb 12, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

add cooldown to dependabot

2 participants