we_are_coded.by CODE · The world, decoded
БГ
GitHub

GitHub flipped the reflex: Dependabot now waits three days before suggesting a new package

GitHubBuilders

From 23 July, Dependabot stops suggesting brand-new package versions right away - by default it waits three days. The rule only applies to routine updates; patches for vulnerabilities still arrive immediately. The reason is an uncomfortable truth about the supply chain: malicious versions live for hours before anyone catches them.

In short
  • From 23 July, Dependabot waits three days by default before opening a pull request for a new package version.
  • Patches for known vulnerabilities don't wait - they keep arriving immediately.
  • Context: around 18 malicious npm packages a day over the year; compromised versions typically get pulled within hours.
Checked on27 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

For years, software had one unspoken rule: update right away, the newest is the safest. GitHub just said out loud that this is no longer true.

The facts: On 23 July 2026 GitHub announced that Dependabot - the bot that suggests package updates across millions of projects - now waits three days by default before opening a pull request for a new version. The rule applies only to routine version updates; patches for known vulnerabilities keep arriving immediately. Context: over the year through May 2026, GitHub's own data logged an average of around 18 malicious npm packages a day, and an analysis of 21 major supply-chain incidents shows that compromised versions typically get pulled within hours of appearing. The window is configurable in dependabot.yml. Source: GitHub, 23.07.2026.

The mechanics are simple, and that's exactly why they work. A poisoned version lives for hours - wait three days and it's already pulled before it ever reaches you. Not because you were smarter, but because you weren't first.

Newest stopped being a synonym for safest.

The lesson holds outside code too. The first hours of anything new - a version, a tool, a service - are the hours where the surprises hide. And nobody hands out a medal for installing first. Three days of patience is the cheapest defense I've seen this year.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→GitHub - The case for a cooldown (Dependabot), 23.07.2026
Original: https://wearecoded.com/en/articles/github-dependabot-cooldown-3-dni.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news