GitHub Security Lab reposted this
Malicious package releases are one of the fastest-moving supply chain threats and automated dependency updates can pick up a malicious package release before maintainers and security researchers have time to catch it. We made a three-day cooldown the default for Dependabot version updates to give new releases a little more time for review before Dependabot opens a pull request. Security updates still open immediately, and if you want, you can adjust the cooldown to fit your project. Read more here: https://lnkd.in/gqC957Yx A big thank you to Jamie Tanna and the Renovate team, Nicky Ringland, Elitsa Bankova, Xueqin Cui and the Google Open Source team for sharing their expertise and ideas. In addition to being awesome people they write awesome content, and you can read about all of our approaches here - Renovate: https://lnkd.in/gwN6wa7n GOSSIP: https://lnkd.in/gZiApJU6 And of course, it wouldn't be possible without the folks at GitHub who helped build this feature: Ankit Kumar Honey, Trevor Rosen, Zach Steindler, Robert Aiken, Marcelo Oliveira, Aaron Cathcart, Xavier René-Corail, Colten Woo 🔒