Skip to content

Conversation

@mbg
Copy link
Member

@mbg mbg commented Jan 27, 2026

See https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#cooldown- for what this does.

Risk assessment

For internal use only. Please select the risk level of this change:

  • Low risk: Changes are fully under feature flags, or have been fully tested and validated in pre-production environments and are highly observable, or are documentation or test only.

Which use cases does this change impact?

  • Testing/None - This change does not impact any CodeQL workflows in production.

How did/will you validate this change?

  • None - I am not validating these changes.

If something goes wrong after this change is released, what are the mitigation and rollback strategies?

  • Rollback - Change can only be disabled by rolling back the release or releasing a new version with a fix.

How will you know if something goes wrong after this change is released?

  • Other - Please provide details.

Are there any special considerations for merging or releasing this change?

  • No special considerations - This change can be merged at any time.

Merge / deployment checklist

  • Confirm this change is backwards compatible with existing workflows.
  • Consider adding a changelog entry for this change.
  • Confirm the readme and docs have been updated if necessary.

@mbg mbg requested a review from a team as a code owner January 27, 2026 11:39
Copilot AI review requested due to automatic review settings January 27, 2026 11:39
@github-actions github-actions bot added the size/XS Should be very easy to review label Jan 27, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds Dependabot cooldown configuration to reduce update PR churn by enforcing a default 7‑day cooldown, with exclusions for core Actions/tooling dependencies.

Changes:

  • Added cooldown.default-days: 7 to the npm Dependabot update configuration.
  • Added cooldown.default-days: 7 to the GitHub Actions Dependabot update configuration.
  • Configured cooldown exclusions for @actions/* (npm) and actions/* (GitHub Actions).

henrymercer
henrymercer previously approved these changes Jan 27, 2026
Copy link
Contributor

@henrymercer henrymercer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@mbg
Copy link
Member Author

mbg commented Jan 27, 2026

@henrymercer had to resolve a merge conflict, so this needs re-approval

henrymercer
henrymercer previously approved these changes Jan 27, 2026
@henrymercer henrymercer added the Rebuild Re-transpile JS & re-generate workflows label Jan 27, 2026
@github-actions github-actions bot removed the Rebuild Re-transpile JS & re-generate workflows label Jan 27, 2026
@github-actions
Copy link
Contributor

Pushed a commit to rebuild the Action. Please mark the PR as ready for review to trigger PR checks.

@github-actions github-actions bot marked this pull request as draft January 27, 2026 14:13
@henrymercer henrymercer marked this pull request as ready for review January 27, 2026 14:13
@henrymercer henrymercer enabled auto-merge January 27, 2026 14:13
@henrymercer henrymercer merged commit b126fac into main Jan 27, 2026
260 of 261 checks passed
@henrymercer henrymercer deleted the mbg/dependabot/cooldown branch January 27, 2026 14:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XS Should be very easy to review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants