You can read more about why Dependabot now waits three days before issuing version update pull requests, and how that short wait can help keep malicious releases out of your code. In other words, why cooldowns are...cool
Dependabot no longer infers.npmrc for npm private registries and now uses a scope property in dependabot.yml to generate the correct config.
github.blog/changelog/2026…