You can read more about why Dependabot now waits three days before issuing version update pull requests, and how that short wait can help keep malicious releases out of your code. In other words, why cooldowns are...cool
Joined May 2017
- tl;dr in 60 days, alerts closed 2 or more years ago are moving to archival storage. you will still be able to download them if you need them.
- Dependabot just got better at using private npm registries!Dependabot no longer infers.npmrc for npm private registries and now uses a scope property in dependabot.yml to generate the correct config. github.blog/changelog/2026…
- See ya never, PATs! github.blog/changelog/2026…



