Skip to content

chore: add a 7-day cooldown to Dependabot version updates - #227

Merged
davidmytton merged 1 commit into
mainfrom
rei/fix/ENG-1375-dependabot-cooldown
Oct 3, 2026
Merged

davidmytton merged 1 commit into
mainfrom
rei/fix/ENG-1375-dependabot-cooldown

Conversation

@arcjet-rei

Copy link
Copy Markdown
Contributor

renovate.json holds new releases for 7 days (minimumReleaseAge), but dependabot.yml had no cooldown, so Dependabot opened version updates for releases only a day old, such as #225.

This sets cooldown.default-days: 7 for the cargo, gomod and github-actions ecosystems. The Dependabot options reference lists default-days as supported for all three. Cooldown applies only to version updates; security updates still open immediately.

One open question: the reference describes a 3-day default cooldown that #225 did not observe. dtolnay/rust-toolchain is pinned to a commit with no release tag, and it is not yet clear whether cooldown applies to updates of that kind.

🤖 Generated with Claude Code

renovate.json already holds new releases for 7 days, but dependabot.yml
had no cooldown, so Dependabot opened version updates for releases a day
old. Set default-days: 7 for the cargo, gomod and github-actions
ecosystems. Security updates are not affected by cooldown.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@arcjet-rei
arcjet-rei requested a review from a team as a code owner October 3, 2026 00:22

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🟢 Low Risk

Decision: Checked

Rationale: The PR makes a narrow configuration-only change to Dependabot by adding a 7-day cooldown for version updates across the existing cargo, gomod, and github-actions ecosystems. No authentication, authorization, runtime code, secrets, dependency manifests, database schema, or workflow execution logic are changed. Security review found no hardcoded secrets or unsafe patterns, and Dependabot security updates are not delayed by this configuration.

Summary of Changes

Adds cooldown.default-days: 7 to each configured Dependabot update ecosystem in .github/dependabot.yml.

Notes

The AI assessed this PR as approvable, but the trust level (1) does not allow auto-approval. A human reviewer must approve this PR.

Review: c39b8f02 | Model: openai/gpt-5.5 | Powered by Arcjet Review

@arcjet-review arcjet-review Bot removed the needs review Awaiting human review label Oct 3, 2026
@davidmytton
davidmytton merged commit fcd11a2 into main Oct 3, 2026
4 checks passed
@davidmytton
davidmytton deleted the rei/fix/ENG-1375-dependabot-cooldown branch October 3, 2026 16:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants