Skip to content

Commit 5403f2b

Browse files
committed
Add 2-day dependabot cooldown to harden against supply chain attacks
1 parent 3d805e6 commit 5403f2b

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

.github/dependabot.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,11 @@ updates:
99
directory: "/"
1010
schedule:
1111
interval: "weekly"
12+
cooldown:
13+
default-days: 2
1214
- package-ecosystem: "npm"
1315
directory: "/priv/static/assets"
1416
schedule:
1517
interval: "weekly"
18+
cooldown:
19+
default-days: 2

0 commit comments

Comments
 (0)