{"id":2804,"date":"2026-07-23T16:00:00","date_gmt":"2026-07-23T16:00:00","guid":{"rendered":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/"},"modified":"2026-07-24T21:59:10","modified_gmt":"2026-07-24T21:59:10","slug":"the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates","status":"publish","type":"post","link":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/","title":{"rendered":"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div id=\"\">\n<p class=\"wp-block-paragraph\">In September 2025, an attacker phished the credentials of a single npm maintainer and revealed booby-trapped variations of chalk, debug, and round a dozen different packages which can be collectively downloaded greater than 2 billion occasions every week. The code rewrote cryptocurrency pockets addresses inside any browser app that loaded it. The poisoned variations have been reside for roughly two hours earlier than the group caught them and npm pulled them.<\/p>\n<p class=\"wp-block-paragraph\">Two hours is a quick response. Nevertheless, additionally it is greater than sufficient time for an automatic replace software to see the brand new model, open a pull request, and put it in entrance of your staff, as a result of model replace tooling is constructed to seize the most recent launch the second it lands.<\/p>\n<p class=\"wp-block-paragraph\">That sample sits behind a rising share of provide chain assaults. The malicious code rides in on a brand-new launch, is revealed to a public registry, and will get pulled into construct pipelines inside minutes, earlier than a human or a scanner has even checked out it.<\/p>\n<p class=\"wp-block-paragraph\">A cooldown modifications that math. Ready just a few days earlier than adopting a brand new launch offers maintainers, safety researchers, and automatic scanners time to identify a malicious model and get it pulled earlier than it ever reaches your pull requests.<\/p>\n<p class=\"wp-block-paragraph\">For non-security model bumps, Dependabot now waits no less than three days after a launch is revealed earlier than opening a pull request. The cooldown configuration choice within the dependabot.yml nonetheless controls the habits, although, so you may select a special cooldown parameter that matches your undertaking.<\/p>\n<h2 id=\"h-two-kinds-of-dependabot-updates\" class=\"wp-block-heading h5-mktg gh-aside-title is-typography-preset-h5\" style=\"margin-top:0\">Two sorts of Dependabot updates<\/h2>\n<p class=\"wp-block-paragraph\">Dependabot is GitHub\u2019s built-in software for preserving dependencies safe and up-to-date, and it does two distinct jobs:<\/p>\n<p>Safety updates\u00a0reply to a identified vulnerability: when an advisory is revealed for a bundle you\u00a0use,\u00a0Dependabot\u00a0points an alert and\u00a0opens a pull request to maneuver you to\u00a0the\u00a0patched model.\u00a0<\/p>\n<p>Model\u00a0updates\u00a0hold\u00a0your dependencies present as new releases come out, no matter your present model\u2019s well being.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The\u00a0new three-day\u00a0cooldown default applies solely to model updates. Safety updates\u00a0nonetheless\u00a0open instantly, since a delay there would maintain again a repair for a flaw that&#8217;s already public. All the pieces\u00a0on this article\u00a0is about model updates, the place the objective is staying\u00a0present,\u00a0and the chance is adopting a launch earlier than it has been vetted.\u00a0<\/p>\n<h2 id=\"h-case-studies-and-github-advisory-database-data\" class=\"wp-block-heading\">Case research and GitHub Advisory Database knowledge<\/h2>\n<p class=\"wp-block-paragraph\">When attackers compromise a preferred bundle, the poisoned model tends to have a brief lifespan. It will get revealed, spreads by way of no matter installs it, and will get caught, often inside hours. The earlier instance was reside for under two hours. Different broadly used packages have adopted the identical arc, with compromised builds of Solana web3.js, Axios, and ua-parser-js every caught inside just a few hours of publication.<\/p>\n<p class=\"wp-block-paragraph\">Extra typically, GitHub sees this sample instantly by way of the GitHub Advisory Database, which catalogs open supply safety advisories throughout ecosystems. Within the yr ending Could 2026, the database revealed greater than 6,500 npm malware advisories, up from roughly 6,200 the yr earlier than, which provides as much as roughly 18 newly cataloged malicious npm packages each day. A cooldown retains you out of that opening window and lets a launch accumulate some scrutiny earlier than it reaches you.<\/p>\n<h2 id=\"h-why-three-days\" class=\"wp-block-heading\">Why three days<\/h2>\n<p class=\"wp-block-paragraph\">Printed malware focusing on fashionable packages tends to get caught quick. A evaluate of 21 broadly reported provide chain incidents between 2018 and 2026 discovered the identical sample: malicious variations of axios, Solana web3.js, ua-parser-js, and Ledger Join Package have been every pulled inside hours of publication, and a cooldown might have filtered out nearly all of these short-lived publishes earlier than anybody put in them.<\/p>\n<p class=\"wp-block-paragraph\">Three days because the default balances two objectives: it pushes you previous the window the place most of those assaults reside, and it doesn\u2019t maintain your dependencies again longer than essential.<\/p>\n<p class=\"wp-block-paragraph\">Different group members have additionally landed on a three-day cooldown (although some go even longer), so this default habits retains Dependabot constant as builders transfer between instruments.<\/p>\n<p class=\"wp-block-paragraph\">You&#8217;ll be able to at all times set an extended or shorter window with Dependabot\u2019s cooldown configuration choice.<\/p>\n<h2 id=\"h-defense-in-depth\" class=\"wp-block-heading\">Protection in depth<\/h2>\n<p class=\"wp-block-paragraph\">A cooldown is constructed for a selected sample: a malicious model that ships, spreads, and will get caught rapidly. It does little towards assaults that play an extended recreation, together with backdoors planted in releases and left dormant, maintainer sabotage, or a compromised construct system. The purpose of the default is to take away a typical and time-sensitive path, to not stand in for the remainder of your defenses.<\/p>\n<p class=\"wp-block-paragraph\">As a result of a cooldown solely addresses the fast-moving case, it must be one layer amongst a number of. Some further steps to take embody pinning dependencies with lockfiles, disabling set up scripts in CI the place you may, scoping the tokens in your construct pipelines, and reviewing updates earlier than they merge.<\/p>\n<p class=\"wp-block-paragraph\">In the event you\u2019d wish to customise your delay for extremely trusted inside packages versus public registries, take a look at the documentation on configuring Dependabot. Or see the Dependabot configuration choices reference for the complete set of cooldown parameters.<\/p>\n<h2 id=\"h-where-we-go-from-here\" class=\"wp-block-heading\">The place we go from right here<\/h2>\n<p class=\"wp-block-paragraph\">That is one step amongst a number of we&#8217;re taking to harden the software program provide chain for everybody who builds on GitHub. It\u2019s on by default, so that you don\u2019t have to alter something to activate it. You can even tune it to suit your workflow.<\/p>\n<div class=\"wp-block-group post-content-cta has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">Inform us the way it performs within the Dependabot group discussions.<\/p>\n<\/div>\n<div class=\"mt-8 mb-8 mb-md-0\">\n<h2 class=\"h5-mktg\">\n\t\tWritten by\t<\/h2>\n<div class=\"author-bio__content\">\n<div class=\"author-bio__avatar\">\n<p>\t\t\t\t\t<img class=\"d-block circle\" src=\"https:\/\/avatars.githubusercontent.com\/u\/61124041?v=4&amp;s=200\" alt=\"Carlin Cherry\" width=\"80\" height=\"80\" loading=\"lazy\" decoding=\"async\"\/><\/p><\/div>\n<div class=\"author-bio__bio f4 lh-default\">\n<p>Carlin is a Product Supervisor at GitHub working in GitHub Superior Safety, with a deal with Dependabot. Her background in software program engineering and knowledge science informs her data-driven strategy to product administration. She lives in Washington along with her companion and their canine, Cookie, and spends her free time biking and taking part in aggressive board video games.<\/p>\n<\/p><\/div><\/div><\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/github.blog\/security\/supply-chain-security\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In September 2025, an attacker phished the credentials of a single npm maintainer and revealed booby-trapped variations of chalk, debug, and round a dozen different packages which can be collectively downloaded greater than 2 billion occasions every week. The code rewrote cryptocurrency pockets addresses inside any browser app that loaded it. The poisoned variations have [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2806,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080","fifu_image_alt":"","jnews-multi-image_gallery":[],"jnews_single_post":[],"jnews_primary_category":[],"jnews_override_bookmark_settings":[],"jnews_social_meta":[],"jnews_override_counter":[],"footnotes":""},"categories":[5],"tags":[253,3269,3270,3272,344,3273,3271],"class_list":["post-2804","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-developer-ai-open-source-ecosystem","tag-case","tag-cooldown","tag-dependabot","tag-issuing","tag-updates","tag-version","tag-waits"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The case for a cooldown: Why Dependabot now waits earlier than issuing model updates - Future News 24<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates - Future News 24\" \/>\n<meta property=\"og:description\" content=\"In September 2025, an attacker phished the credentials of a single npm maintainer and revealed booby-trapped variations of chalk, debug, and round a dozen different packages which can be collectively downloaded greater than 2 billion occasions every week. The code rewrote cryptocurrency pockets addresses inside any browser app that loaded it. The poisoned variations have [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/\" \/>\n<meta property=\"og:site_name\" content=\"Future News 24\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-23T16:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-24T21:59:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080\" \/><meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080\" \/>\n<meta name=\"author\" content=\"Future News 24\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Future News 24\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/\"},\"author\":{\"name\":\"Future News 24\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#\\\/schema\\\/person\\\/cecad1bde21cfc357cf70128144d6c83\"},\"headline\":\"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates\",\"datePublished\":\"2026-07-23T16:00:00+00:00\",\"dateModified\":\"2026-07-24T21:59:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/\"},\"wordCount\":1012,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-security-logo-github-blocks.png?fit=1920%2C1080\",\"keywords\":[\"case\",\"cooldown\",\"Dependabot\",\"issuing\",\"Updates\",\"version\",\"waits\"],\"articleSection\":[\"Developer AI &amp; Open-Source Ecosystem\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/\",\"url\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/\",\"name\":\"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates - Future News 24\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-security-logo-github-blocks.png?fit=1920%2C1080\",\"datePublished\":\"2026-07-23T16:00:00+00:00\",\"dateModified\":\"2026-07-24T21:59:10+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/#primaryimage\",\"url\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-security-logo-github-blocks.png?fit=1920%2C1080\",\"contentUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-security-logo-github-blocks.png?fit=1920%2C1080\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/07\\\/23\\\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/futurenews24.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#website\",\"url\":\"https:\\\/\\\/futurenews24.com\\\/\",\"name\":\"Future News 24\",\"description\":\"The Smart Hub for AI and Next-Gen Innovation\",\"publisher\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/futurenews24.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#organization\",\"name\":\"Future News 24\",\"url\":\"https:\\\/\\\/futurenews24.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/futurenews24.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/fn24-favicon.png\",\"contentUrl\":\"https:\\\/\\\/futurenews24.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/fn24-favicon.png\",\"width\":250,\"height\":250,\"caption\":\"Future News 24\"},\"image\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#\\\/schema\\\/person\\\/cecad1bde21cfc357cf70128144d6c83\",\"name\":\"Future News 24\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g\",\"caption\":\"Future News 24\"},\"sameAs\":[\"https:\\\/\\\/futurenews24.com\"],\"url\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/author\\\/mridulpahuja20\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates - Future News 24","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/","og_locale":"en_US","og_type":"article","og_title":"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates - Future News 24","og_description":"In September 2025, an attacker phished the credentials of a single npm maintainer and revealed booby-trapped variations of chalk, debug, and round a dozen different packages which can be collectively downloaded greater than 2 billion occasions every week. The code rewrote cryptocurrency pockets addresses inside any browser app that loaded it. The poisoned variations have [&hellip;]","og_url":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/","og_site_name":"Future News 24","article_published_time":"2026-07-23T16:00:00+00:00","article_modified_time":"2026-07-24T21:59:10+00:00","og_image":[{"url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080","type":"","width":"","height":""},{"url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080","type":"","width":"","height":""}],"author":"Future News 24","twitter_card":"summary_large_image","twitter_image":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080","twitter_misc":{"Written by":"Future News 24","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/#article","isPartOf":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/"},"author":{"name":"Future News 24","@id":"https:\/\/futurenews24.com\/#\/schema\/person\/cecad1bde21cfc357cf70128144d6c83"},"headline":"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates","datePublished":"2026-07-23T16:00:00+00:00","dateModified":"2026-07-24T21:59:10+00:00","mainEntityOfPage":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/"},"wordCount":1012,"commentCount":0,"publisher":{"@id":"https:\/\/futurenews24.com\/#organization"},"image":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080","keywords":["case","cooldown","Dependabot","issuing","Updates","version","waits"],"articleSection":["Developer AI &amp; Open-Source Ecosystem"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/","url":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/","name":"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates - Future News 24","isPartOf":{"@id":"https:\/\/futurenews24.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/#primaryimage"},"image":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080","datePublished":"2026-07-23T16:00:00+00:00","dateModified":"2026-07-24T21:59:10+00:00","breadcrumb":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/#primaryimage","url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080","contentUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-github-blocks.png?fit=1920%2C1080"},{"@type":"BreadcrumbList","@id":"https:\/\/futurenews24.com\/index.php\/2026\/07\/23\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/futurenews24.com\/"},{"@type":"ListItem","position":2,"name":"The case for a cooldown: Why Dependabot now waits earlier than issuing model updates"}]},{"@type":"WebSite","@id":"https:\/\/futurenews24.com\/#website","url":"https:\/\/futurenews24.com\/","name":"Future News 24","description":"The Smart Hub for AI and Next-Gen Innovation","publisher":{"@id":"https:\/\/futurenews24.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/futurenews24.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/futurenews24.com\/#organization","name":"Future News 24","url":"https:\/\/futurenews24.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/futurenews24.com\/#\/schema\/logo\/image\/","url":"https:\/\/futurenews24.com\/wp-content\/uploads\/2026\/06\/fn24-favicon.png","contentUrl":"https:\/\/futurenews24.com\/wp-content\/uploads\/2026\/06\/fn24-favicon.png","width":250,"height":250,"caption":"Future News 24"},"image":{"@id":"https:\/\/futurenews24.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/futurenews24.com\/#\/schema\/person\/cecad1bde21cfc357cf70128144d6c83","name":"Future News 24","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g","caption":"Future News 24"},"sameAs":["https:\/\/futurenews24.com"],"url":"https:\/\/futurenews24.com\/index.php\/author\/mridulpahuja20\/"}]}},"_links":{"self":[{"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/posts\/2804","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/comments?post=2804"}],"version-history":[{"count":1,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/posts\/2804\/revisions"}],"predecessor-version":[{"id":2805,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/posts\/2804\/revisions\/2805"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/media\/2806"}],"wp:attachment":[{"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/media?parent=2804"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/categories?post=2804"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/tags?post=2804"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}