Three days is now the default.
Security updates are still immediate.
Map sanitized update policies after Dependabot's new default. Separate version from security updates, defaults from explicit rules, and include/exclude intent from observed PR and CI evidence—without pasting repository configuration or dependency identities.
Dependabot cooldown policy map
| Policy | Ecosystem / class | Source / days / SemVer | Match / schedule / group | Critical exception / test | Evidence / owner | Decision / result |
|---|
Cooldown, security-exception and observed-result queue
“Evidence recorded” proves only coherent abstract metadata. This page did not inspect a repository, Dependabot YAML, registry release, dependency, advisory, generated PR, CI or logs; change configuration; delay/open a PR; assess a release; or prove supply-chain safety.
Zero-repository-data boundary: all free analysis stays in this browser. Enter only fictional aliases, enumerated states, a 0–90 day number and safe evidence references. Never paste a real repository/org, dependabot.yml, dependency/package, manifest/lockfile, advisory, PR/log, token or secret. This page does not parse or write configuration, inspect registry/advisory facts, open/delay PRs, run CI, approve a merge or certify a release. Authorized platform, security and repository owners control every real action.
$15 Dependabot Cooldown Policy Evidence Pack
Export an editable matrix for up to 100 sanitized policy paths: default versus explicit source, version/security split, SemVer and include/exclude priority, schedule/group conflicts, critical exceptions, observed PR/CI tests, sign-off and PMF ledger.
- up to 100 sanitized policy paths
- GitHub default versus explicit and opt-out matrix
- version update versus immediate security update split
- SemVer days and include/exclude precedence queue
- schedule/group conflicts and observed PR/CI tests
- 30-day qualified-visit, use, intent and paid ledger
Current Dependabot default and configuration controls
PMF pre-judgment 84/100 · $15 one-time policy evidence pack under strong Dependabot, Renovate and internal dependency-governance substitutes