Skip to content

Resolve zizmor lints#130

Merged
facutuesca merged 1 commit intomainfrom
add-cooldown
Oct 23, 2025
Merged

Resolve zizmor lints#130
facutuesca merged 1 commit intomainfrom
add-cooldown

Conversation

@Ninja3047
Copy link
Contributor

Fix new lint that recommends adding cooldowns to dependabot workflows to mitigate supply chain attacks

https://github.com/trailofbits/cookiecutter-python/security/code-scanning/51
https://github.com/trailofbits/cookiecutter-python/security/code-scanning/52
https://github.com/trailofbits/cookiecutter-python/security/code-scanning/53
https://github.com/trailofbits/cookiecutter-python/security/code-scanning/54

I put 7 days but not sure if that's too long since that's also easily 7 days of not applying security patches
Could be convinced to lower to 3 days or 5 days

@facutuesca facutuesca self-requested a review October 23, 2025 15:57
@facutuesca facutuesca merged commit c4cdc90 into main Oct 23, 2025
6 checks passed
@facutuesca facutuesca deleted the add-cooldown branch October 23, 2025 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants