[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgZJNOq0Fse5V-ek46cVpNTZBYx-i7FQCOFfUegn3L74":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"57f6c08c-6a91-4285-b508-981d26154c58","GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption","github-adds-3-day-dependabot-cooldown-to-limit-poisoned-package-adoption-c2fbf6","GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. \"The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project,\" the Microsoft-owned subsidiary said. According to GitHub, the","GitHub has introduced a new default three-day cooldown period for Dependabot version updates. This change aims to mitigate supply chain attacks where threat actors push poisoned package versions that are quickly adopted before being removed. While security updates will still be pushed immediately, the cooldown for regular version updates provides a buffer to identify and mitigate malicious packages.","GitHub Dependabot adds a 3-day cooldown for version updates to prevent poisoned package adoption.","GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption Ravie LakshmananJul 27, 2026Software Supply Chain \u002F DevSecOps GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. \"The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project,\" the Microsoft-owned subsidiary said. According to GitHub, the three-day cooldown default only applies to version updates, which are designed to keep software dependencies up-to-date. Security updates will continue to be pushed right away, permitting Dependabot to issue an alert and open a pull request to move the project to the patched version. With this update, the idea is to handle scenarios where a threat actor manages to push a poisoned version of a popular package, which then gets quickly pulled by downstream projects before that version is yanked from the registry. Although such trojanized packages are short-lived, the time period for which they remain accessible is enough to expand the blast radius of a supply chain attack. GitHub said it arrived at three days as the default as it considers the duration to be in the goldilocks zone. \"Three days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn't hold your dependencies back longer than necessary,\" it added. At the same time, the software development platform emphasized that the control should be just one layer of defense among several others, including pinning dependencies with lockfiles, disabling install scripts in CI, scoping the tokens in build pipelines, and reviewing updates before they merge. \"A cooldown is built for a specific pattern: a malicious version that ships, spreads, and gets caught quickly,\" GitHub said. \"It does little against attacks that play a longer game, including backdoors planted in releases and left dormant, maintainer sabotage, or a compromised build system.\" It's worth noting similar cooldown controls have been announced across various package ecosystems over the past year, including Microsoft Visual Studio Code (VS Code), Ruby, Bun, npm, pnpm, and Yarn. GitHub's time-based defense comes as the maintainers of the Python Package Index (PyPI) announced plans to block maintainers from adding new files to a package release after 14 days have passed since its publication. \"The measure is intended to prevent attackers who compromise publishing tokens or workflows from poisoning old, trusted releases,\" PyPI noted. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Application Security, CI\u002FCD Security, DevSecOps, GitHub, Open Source, Package Security, Python, Software Supply Chain ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See","https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fgithub-adds-3-day-dependabot-cooldown.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEiFpE4BZgV3wILI8fonm9742zR85yLmBdM2ExXv-uTUS1StV04ZlNVVIwV6FjjhYLZUAFk-DAIInwp3mlXa2W2xekDA_EqSl1UiHrKCgocsjhVAKlvCD48QnlVdUdCIQia7T4ilS65ZFptdi_wox0Q9brVTdpoqDNTvpCjg0D6BslyCAPRzY7QMyUoYNkv-\u002Fs1600\u002Fgitbot.jpg","2026-07-27T08:01:23+00:00","2026-07-27T10:00:19.67504+00:00",7,[18,21,24],{"name":19,"type":20},"Dependabot","product",{"name":22,"type":23},"GitHub","vendor",{"name":25,"type":23},"Microsoft","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":26,"icon":28,"name":29,"slug":30},null,"Supply Chain","supply-chain",[32,37,39],{"category":33},{"id":34,"icon":28,"name":35,"slug":36},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":38},{"id":26,"icon":28,"name":29,"slug":30},{"category":40},{"id":41,"icon":28,"name":42,"slug":43},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",[]]