Skip to content

chore: add Dependabot cooldown — Go, GitHub Actions#2

Open
andrei-ifrim wants to merge 1 commit into
mainfrom
chore/dependabot-cooldown-adr-011
Open

chore: add Dependabot cooldown — Go, GitHub Actions#2
andrei-ifrim wants to merge 1 commit into
mainfrom
chore/dependabot-cooldown-adr-011

Conversation

@andrei-ifrim

Copy link
Copy Markdown

https://www.notion.so/ADR-011-Introduce-Cooldown-Period-for-Dependency-Updates-2e37256fbc328194b407d081692279d5
https://www.notion.so/Safe-deployment-guardrails-for-SDLC-controls-rollout-3507256fbc3280368c22fc45fe65b8dd

Adds a 3-day cooldown to Dependabot dependency updates for Go, GitHub Actions, as required by ADR-011.

The cooldown delays Dependabot PR creation by 3 days after a new package version is published. This provides a buffer to detect supply chain attacks or compromised releases before the organisation automatically adopts them.

Changes made:

  • Go: added cooldown: default-days: 3
  • GitHub Actions: added cooldown: default-days: 3

No other changes. All existing configuration — ignore rules, groups, registry settings, schedules, and PR limits — is untouched.

Risk classification: MEDIUM — push-to-main via shared-actions (safety fix in place): release.yml, docker_edge.yml, test.yml

@adrian-marza-oaknorth adrian-marza-oaknorth left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

NOT SAFE TO MERGE (ADR-011): Post-merge test.yml fires on bare on: push (all branches, no path filter). Merging this .github/dependabot.yml cooldown change will trigger the full test + golangci-lint pipeline.

Comment thread .github/dependabot.yml
timezone: Europe/London
cooldown:
default-days: 3
open-pull-requests-limit: 10

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

NOT SAFE TO MERGE (ADR-011): test.yml triggers on bare on: push with no branch or path filter — merging this cooldown change will trigger the full test + lint pipeline. Add a path filter to test.yml before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants