Commit 1be4ac1
committed
Set a dependabot cooldown.
From Zizmor docs:
> By default, Dependabot does not perform any cooldown on dependency updates. In other words, a regularly scheduled Dependabot run may perform an update on a dependency that was just released moments before the run began. This presents both stability and supply-chain security risks
https://docs.zizmor.sh/audits/#dependabot-cooldown1 parent 2c58988 commit 1be4ac1
1 file changed
+2
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| 14 | + | |
| 15 | + | |
0 commit comments