Dependabot version updates introduce default package cooldown

GitHub's Dependabot has introduced a mandatory three-day cooldown period for new package releases before it suggests updates. This measure is designed to mitigate supply chain attacks by allowing time for the community to identify and report malicious or broken code.
Why it matters
Automated dependency management is a critical vector for cyberattacks; this change adds a layer of security to the software development lifecycle.
Back to changelog Improvement July 14, 2026 • 1 minute read Dependabot version updates introduce default package cooldown Dependabot now waits until a new release has been available on its registry for at least three days before opening a version update pull request. This cooldown is now the default and requires no configuration.
The article is a straightforward technical announcement regarding platform security updates.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in