Skip to content

Commit a0eeda9

Browse files
committed
Introduced 7 day cooldown for updating dependencies
Except for airlift & trino dependencies which we control and release
1 parent 62ad450 commit a0eeda9

File tree

1 file changed

+11
-0
lines changed

1 file changed

+11
-0
lines changed

.github/dependabot.yml

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,19 @@ updates:
44
directory: "/"
55
schedule:
66
interval: "weekly"
7+
cooldown:
8+
# Apply 7 day cooldown to avoid updating dependencies right away. This reduces the opportunity window
9+
# when supply chain is compromised.
10+
default-days: 7
711
- package-ecosystem: "maven"
812
directory: "/"
913
schedule:
1014
interval: "daily"
1115
open-pull-requests-limit: 10
16+
cooldown:
17+
# Apply 7 day cooldown to avoid updating dependencies right away. This reduces the opportunity window
18+
# when supply chain is compromised. This doesn't apply to the dependencies that we own and release.
19+
default-days: 7
20+
exclude:
21+
- io.airlift:*
22+
- io.trino:*

0 commit comments

Comments
 (0)