Skip to content

chore: add Dependabot cooldown — Python (pip)#9

Open
andrei-ifrim wants to merge 2 commits into
mainfrom
chore/dependabot-cooldown-adr-011
Open

chore: add Dependabot cooldown — Python (pip)#9
andrei-ifrim wants to merge 2 commits into
mainfrom
chore/dependabot-cooldown-adr-011

Conversation

@andrei-ifrim

Copy link
Copy Markdown
Contributor

https://www.notion.so/ADR-011-Introduce-Cooldown-Period-for-Dependency-Updates-2e37256fbc328194b407d081692279d5
https://www.notion.so/Safe-deployment-guardrails-for-SDLC-controls-rollout-3507256fbc3280368c22fc45fe65b8dd

Adds a 3-day cooldown to Dependabot dependency updates for Python (pip), as required by ADR-011.

The cooldown delays Dependabot PR creation by 3 days after a new package version is published. This provides a buffer to detect supply chain attacks or compromised releases before the organisation automatically adopts them.

Changes made:

  • Python (pip): added cooldown: default-days: 3

No other changes. All existing configuration — ignore rules, groups, registry settings, schedules, and PR limits — is untouched.

Risk classification: LOW — no workflows directory

@andrei-ifrim andrei-ifrim requested a review from a team as a code owner May 26, 2026 12:36

@adrian-marza-oaknorth adrian-marza-oaknorth left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved: dependabot.yml cooldown config is syntactically correct (ADR-011). No CI pipeline will trigger post-merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants