Skip to content

Conversation

@rH4rtinger
Copy link
Collaborator

@rH4rtinger rH4rtinger commented Dec 1, 2025

Please check before merging

  • Is the content of the README.md file still up-to-date?
  • Have you added an entry to the CHANGELOG.md?
  • Is the pull request title written in the Conventional Commits format?
  • VSCode: Did you write e2e tests?
  • VSCode: Did you follow the UX Guidelines?

Description

added cooldown of 7 days to dependabot.

Cooldown of 7 days was added because most of the security breaches of the dependencies will be resolved in about 7 days after occuring.
Because we wait 7 days after every dependency update, the most of the attacks will not affect us.
See this blog for further explanations

@rH4rtinger rH4rtinger requested a review from wglanzer December 1, 2025 07:06
@rH4rtinger rH4rtinger requested a review from a team as a code owner December 1, 2025 07:06
@rH4rtinger rH4rtinger self-assigned this Dec 1, 2025
@sonarqubecloud
Copy link

sonarqubecloud bot commented Dec 1, 2025

Copy link
Member

@wglanzer wglanzer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It would be nice if you could add a short explanation about why you introduced this cooldown in this PR.

@rH4rtinger
Copy link
Collaborator Author

It would be nice if you could add a short explanation about why you introduced this cooldown in this PR.

@wglanzer added more explanation to the description of this PR

@rH4rtinger rH4rtinger merged commit 789f54f into main Dec 1, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants