GITHUB has implemented a 3-day cooldown for its Dependabot service to help users avoid the adoption of vulnerable packages in their software supply chains. This measure aims to enhance security by preventing the rapid use of potentially harmful dependencies. The change reflects the industry's ongoing efforts to address software supply chain threats effectively.
GitHub introduces 3 day Dependabot cooldown to stop risky updates
CyberSIXT Evidence Panel
Source marked as original reporting
Article by CyberSIXT