GitHub has implemented a 3-day waiting period for its Dependabot tool before automatically updating to newly released software packages, designed to reduce the risk of rapidly adopting malicious or poisoned packages that attackers inject into repositories
Read the full article: https://thehackernews.com/2026/07/github-adds-3-day-dependabot-cooldown.html