Repository navigation
Group Dependabot updates with a 14-day cooldown - #1907
Bill Schnurr (bschnurr) merged 1 commit into
Conversation
Co-authored-by: Copilot <[email protected]> Copilot-Session: ce6aeb0a-6210-4716-8a84-2f3e7555625f
|
🔒 Automated review in progress — Heejae Chang (@heejaechang) is auto-reviewing this PR. |
|
Result: Verification detailsVerification: Isolated verification observed failures that were not classified as caused by this PR: Dependency and test discovery. Summary: Container checks passed: the YAML parses, GitHub Actions retains its weekly schedule and wildcard group, and the cooldown is integer 14. No relevant existing tests were found under src/test, and the PR adds none. Git-based discovery and diff validation failed because the container lacks Git metadata. Static configuration checks passed, but live Dependabot behavior was not exercised. Test runs: 1 passed, 1 failed
❌
|
Heejae Chang (heejaechang)
left a comment
There was a problem hiding this comment.
Approved via Review Center.
7c894fc
into
microsoft:main
Summary
The delay follows the supply-chain hardening pattern used by python/cpython-devcontainers and avoids the highest-risk window immediately after a new dependency release.
Validation
cooldown.default-days: 14git diff --check