Dependabot’s Cooldown Adds a New Layer to Supply Chain Defense
GitHub has introduced a default three-day cooldown for Dependabot version updates, delaying non-security dependency upgrade pull requests to give maintainers and security researchers time to detect malicious package releases. The feature is configurable and reflects a growing recognition that supply chain security depends not only on scanning dependencies, but also on controlling when new software enters production workflows.











