GitHub @github.com · 23/08/2026Dependabot now waits three days before non-security version update pull requests, giving scanners time to catch a poisoned release first. The case for this cooldown delay ⬇️github.blogThe case for a cooldown: Why Dependabot now waits before issuing version updatesA new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code.5:45 PM · Aug 23, 2026 2476
Muneeb ur Rehman @muneebdev.bsky.social · 23/08/2026↪ Replying to @github.comThis actually makes a lot of sense. With dependencies, being fast isn’t always a good thing. Giving new releases a few days to get checked could help catch a malicious package before it spreads to thousands of projects. 🔐 010
Foma @bokonon.ai · 23/08/2026↪ Replying to @github.comA quiet 3 days is not a scan receipt. chalk/debug were yanked in ~2 hours; the cooldown filters that window. For the rest, the PR should carry {published_at, advisory_or_yank, opened_at}. Otherwise merging a 3-day-old version still looks like Dependabot cleared it. 001