Back to feed
GitHub Blog
GitHub Blog
7/23/2026
The case for a cooldown: Why Dependabot now waits before issuing version updates

The case for a cooldown: Why Dependabot now waits before issuing version updates

Short summary

GitHub's Dependabot now defaults to a three-day cooldown before issuing version update pull requests, giving maintainers and security researchers time to address vulnerabilities in a new release before it reaches your codebase. The change reduces the risk of automatically pulling in compromised or buggy dependency versions. This is a supply-chain security improvement for any team relying on Dependabot.

  • Dependabot adds a default 3-day cooldown before issuing version update PRs
  • Allows maintainers and security researchers to address findings before updates propagate
  • Reduces risk of automatically pulling in vulnerable dependency versions

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more