Repository navigation
chore: add a 7-day cooldown to Dependabot version updates - #227
Conversation
renovate.json already holds new releases for 7 days, but dependabot.yml had no cooldown, so Dependabot opened version updates for releases a day old. Set default-days: 7 for the cargo, gomod and github-actions ecosystems. Security updates are not affected by cooldown. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Arcjet Review — 🟢 Low Risk
Decision: Checked
Rationale: The PR makes a narrow configuration-only change to Dependabot by adding a 7-day cooldown for version updates across the existing cargo, gomod, and github-actions ecosystems. No authentication, authorization, runtime code, secrets, dependency manifests, database schema, or workflow execution logic are changed. Security review found no hardcoded secrets or unsafe patterns, and Dependabot security updates are not delayed by this configuration.
Summary of Changes
Adds cooldown.default-days: 7 to each configured Dependabot update ecosystem in .github/dependabot.yml.
Notes
The AI assessed this PR as approvable, but the trust level (1) does not allow auto-approval. A human reviewer must approve this PR.
Review: c39b8f02 | Model: openai/gpt-5.5 | Powered by Arcjet Review
renovate.jsonholds new releases for 7 days (minimumReleaseAge), butdependabot.ymlhad nocooldown, so Dependabot opened version updates for releases only a day old, such as #225.This sets
cooldown.default-days: 7for thecargo,gomodandgithub-actionsecosystems. The Dependabot options reference listsdefault-daysas supported for all three. Cooldown applies only to version updates; security updates still open immediately.One open question: the reference describes a 3-day default cooldown that #225 did not observe.
dtolnay/rust-toolchainis pinned to a commit with no release tag, and it is not yet clear whether cooldown applies to updates of that kind.🤖 Generated with Claude Code