From 23 July, Dependabot stops suggesting brand-new package versions right away - by default it waits three days. The rule only applies to routine updates; patches for vulnerabilities still arrive immediately. The reason is an uncomfortable truth about the supply chain: malicious versions live for hours before anyone catches them.
- From 23 July, Dependabot waits three days by default before opening a pull request for a new package version.
- Patches for known vulnerabilities don't wait - they keep arriving immediately.
- Context: around 18 malicious npm packages a day over the year; compromised versions typically get pulled within hours.
For years, software had one unspoken rule: update right away, the newest is the safest. GitHub just said out loud that this is no longer true.
The mechanics are simple, and that's exactly why they work. A poisoned version lives for hours - wait three days and it's already pulled before it ever reaches you. Not because you were smarter, but because you weren't first.
The lesson holds outside code too. The first hours of anything new - a version, a tool, a service - are the hours where the surprises hide. And nobody hands out a medal for installing first. Three days of patience is the cheapest defense I've seen this year.