Skip to content

add cooldown of 7 days to gradle package updates#1458

Merged
Jonopono123 merged 1 commit into
mainfrom
NIAD-3448
Apr 14, 2026
Merged

add cooldown of 7 days to gradle package updates#1458
Jonopono123 merged 1 commit into
mainfrom
NIAD-3448

Conversation

@Jonopono123
Copy link
Copy Markdown
Contributor

What

Add default cooldown of 7 days to dependabot.yml for gradle packages.

Why

Following on from recent compromised package updates, we want to enforce a 7 day cooldown on any package updates to ensure that we're not potentially bringing dangerous updates into our deployments.

Type of change

Please delete options that are not relevant.

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Internal change (non-breaking change with no effect on the functionality affecting end users)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)

Checklist:

  • I have performed a self-review of my code
  • My changes generate no new warnings
  • New and existing unit tests pass locally with my changes

@Jonopono123 Jonopono123 requested a review from a team as a code owner April 14, 2026 13:57
@github-actions
Copy link
Copy Markdown

Looks good. No mutations were possible for these changes.
See https://pitest.org

@Jonopono123 Jonopono123 merged commit 5044011 into main Apr 14, 2026
13 checks passed
@Jonopono123 Jonopono123 deleted the NIAD-3448 branch April 14, 2026 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants