Skip to content

Add Dependabot Cooldown#13

Merged
lynnfaraday merged 2 commits into
mainfrom
dependabot-cooldown
May 22, 2026
Merged

Add Dependabot Cooldown#13
lynnfaraday merged 2 commits into
mainfrom
dependabot-cooldown

Conversation

@lynnfaraday
Copy link
Copy Markdown
Collaborator

@lynnfaraday lynnfaraday commented May 20, 2026

Overview

Add a dependabot cooldown, same as CareEvolution/MyDataHelpsUI#610

Security

REMINDER: All file contents are public.

  • I have ensured no secure credentials or sensitive information remain in code, metadata, comments, etc.
  • There are no temporary testing changes committed such as API base URLs, access tokens, print/log statements, etc.
  • These changes do not introduce any security risks, or any such risks have been properly mitigated.

Describe briefly what security risks you considered, why they don't apply, or how they've been mitigated.

Consider "Squash and merge" as needed to keep the commit history reasonable on main.

Reviewers

Assign to the appropriate reviewer(s). Minimally, a second set of eyes is needed ensure no non-public information is published. Consider also including:

  • Subject-matter experts
  • Style/editing reviewers
  • Others requested by the content owner

@lynnfaraday lynnfaraday requested a review from skyguy94 May 20, 2026 13:58
Copy link
Copy Markdown

@skyguy94 skyguy94 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This adds support for dependabot package updates. Those are different than dependabot security updates. One path is for vulnerabilities and the other is for bugs.

If you want automatic package updates, then this is fine.

https://docs.github.com/en/code-security/concepts/supply-chain-security/about-dependabot-security-updates

@lynnfaraday
Copy link
Copy Markdown
Collaborator Author

Since this is a public demo, I do think it's worth keeping the packages up to date. I dialed back the frequency to monthly though because we don't need to be quite so aggressive.

@lynnfaraday lynnfaraday merged commit 66767cb into main May 22, 2026
5 checks passed
@lynnfaraday lynnfaraday deleted the dependabot-cooldown branch May 22, 2026 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants