Skip to content

chore(dependabot): add 3-day cooldown for supply-chain safety#85

Merged
tnj merged 1 commit into
mainfrom
chore/dependabot-cooldown
Jun 10, 2026
Merged

chore(dependabot): add 3-day cooldown for supply-chain safety#85
tnj merged 1 commit into
mainfrom
chore/dependabot-cooldown

Conversation

@tnj

@tnj tnj commented Jun 9, 2026

Copy link
Copy Markdown
Member

概要

サプライチェーン攻撃のリスク低減のため、Dependabot に 3日間の cooldown を設定します。新しく公開された依存バージョンへの更新 PR を 3 日間遅延させ、公開直後の悪意あるバージョンを取り込みにくくします。

変更内容

  • updates エントリに cooldown.default-days: 3 を追加

🤖 Generated with Claude Code

@tnj tnj requested a review from enomoto-kazuya as a code owner June 9, 2026 09:13
@github-actions

github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

DeployGate Upload Information

Item Content
🔄 Revision 110
📱 App Details View on DeployGate
🔗 Distribution Page https://deploygate.com/distributions/4e531da5dfd007964eb0340bba094e8fbfbe89f2
📲 Open on Mobile QR Code

@enomoto-kazuya enomoto-kazuya left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@tnj tnj merged commit 9faed43 into main Jun 10, 2026
4 checks passed
@tnj tnj deleted the chore/dependabot-cooldown branch June 10, 2026 07:45
@tnj

tnj commented Jun 10, 2026

Copy link
Copy Markdown
Member Author

thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants