Skip to content

Commit 4904a6e

Browse files
committed
add direct description to not rely on blog
1 parent d997923 commit 4904a6e

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

.github/dependabot.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@ updates:
1414
- "version-update:semver-patch"
1515
cooldown:
1616
# https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
17+
# Cooldowns protect against supply chain attacks by avoiding the
18+
# highest-risk window immediately after new releases.
1719
default-days: 14
1820
- package-ecosystem: "pip"
1921
directory: "/Tools/"

0 commit comments

Comments
 (0)