تأخير Dependabot لحماية الحزم
GitHub has implemented a three-day cooldown period for Dependabot to mitigate the adoption of compromised packages.
لماذا يهم هذا الخبر؟
تخفيف خطر الحزم الملوثة
سياق الخبر
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project," the Microsoft-owned subsidiary said. According to GitHub, the
فتح الخبر الأصلي