Skip to content

ci: introduce 7-day dependabot cooldown#827

Merged
benhoyt merged 1 commit intocanonical:masterfrom
benhoyt:dependabot-cooldown
Mar 30, 2026
Merged

ci: introduce 7-day dependabot cooldown#827
benhoyt merged 1 commit intocanonical:masterfrom
benhoyt:dependabot-cooldown

Conversation

@benhoyt
Copy link
Copy Markdown
Contributor

@benhoyt benhoyt commented Mar 26, 2026

Zizmor actually flags this, but it's a warning at the level we're using rather than an error.

Zizmor actually flags this, but it's a warning at the level we're using
rather than an error.
@benhoyt benhoyt requested a review from tonyandrewmeyer March 26, 2026 23:19
Copy link
Copy Markdown
Contributor

@tonyandrewmeyer tonyandrewmeyer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! I think we should do this across all our repositories.

Comment on lines +18 to +19
cooldown:
default-days: 7
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool-downs only work for regular updates, not security ones so I think this will have no impact, since we limit dependabot to only security updates just above this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, okay. It's a bit confusing, but I think I might leave it in case we change open-pull-requests-limit to include non-security updates in future.

@benhoyt
Copy link
Copy Markdown
Contributor Author

benhoyt commented Mar 30, 2026

Opened canonical/operator#2396 to track the rest of our repos.

@benhoyt benhoyt merged commit df9d2ec into canonical:master Mar 30, 2026
22 of 23 checks passed
@benhoyt benhoyt deleted the dependabot-cooldown branch March 30, 2026 03:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants