⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

GitHub Introduces 3-Day Dependabot Cooldown to Mitigate Poisoned Package Attacks

July 27, 2026

GitHub has announced a new cooldown mechanism for Dependabot that introduces a mandatory three-day waiting period before opening pull requests for version updates. This delay is designed to reduce the risk of downstream projects automatically adopting malicious package versions that are quickly published and then yanked from registries.

The cooldown configuration option in the dependabot.yml file remains customizable, allowing projects to adjust the parameter as needed. Security updates are exempt from this delay and will continue to be pushed immediately to ensure critical patches are applied without delay.

GitHub selected three days as the default cooldown period, describing it as the “goldilocks zone” that balances the need to stay current with dependencies while avoiding the window during which most supply chain attacks occur. The company emphasized that this control should be part of a broader defense strategy that includes pinning dependencies with lockfiles, disabling install scripts in CI, scoping tokens in build pipelines, and reviewing updates before merging.

The cooldown is specifically designed to counter attacks where a malicious version is shipped, spreads rapidly, and is caught quickly. It is less effective against longer-term threats such as backdoors planted in releases, maintainer sabotage, or compromised build systems.

Similar cooldown controls have been adopted across various package ecosystems, including Microsoft Visual Studio Code, Ruby, Bun, npm, pnpm, and Yarn. Additionally, the Python Package Index (PyPI) has announced plans to block maintainers from adding new files to a package release after 14 days have passed since publication, aiming to prevent attackers from poisoning old, trusted releases.

CVEs: CVE-2026-50522

Companies: GitHub, Microsoft, Python Package Index (PyPI)

Products: Dependabot, Visual Studio Code, Ruby, Bun, npm, pnpm, Yarn