Skip to content

chore: add 7-day Dependabot cooldown#587

Open
theorderingmachine wants to merge 2 commits intoslackapi:mainfrom
theorderingmachine:chore/dependabot-cooldown-7-days
Open

chore: add 7-day Dependabot cooldown#587
theorderingmachine wants to merge 2 commits intoslackapi:mainfrom
theorderingmachine:chore/dependabot-cooldown-7-days

Conversation

@theorderingmachine
Copy link
Copy Markdown

@theorderingmachine theorderingmachine commented Apr 6, 2026

Adds a 7-day Dependabot cooldown to the npm and github-actions update blocks in .github/dependabot.yml, while excluding @slack/* packages from the npm cooldown so Slack-owned packages can still update immediately.

This is partly motivated by prior workflow hardening / analysis work around zizmor in this repo and related health-score-driven PRs:

The goal here is to slow down most ecosystem updates a bit, without getting in the way of first-party @slack/* package updates or adjacent workflow security work.

@theorderingmachine theorderingmachine requested a review from a team as a code owner April 6, 2026 19:22
@salesforce-cla
Copy link
Copy Markdown

salesforce-cla bot commented Apr 6, 2026

Thanks for the contribution! Before we can merge this, we need @openclaw to sign the Salesforce Inc. Contributor License Agreement.

@theorderingmachine theorderingmachine force-pushed the chore/dependabot-cooldown-7-days branch from a1b7f2d to b6b84b7 Compare April 6, 2026 19:24
@salesforce-cla
Copy link
Copy Markdown

salesforce-cla bot commented Apr 6, 2026

Thanks for the contribution! Before we can merge this, we need @theorderingmachine to sign the Salesforce Inc. Contributor License Agreement.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant