#GitHub's Dependabot now waits 3 days by default before opening pull requests for new non-security dependency versions.

The delay gives security scanners and the community more time to detect and remove malicious releases before they're integrated into projects.

Read the full story on InfoQ 👉 https://bit.ly/4xeUgVY

#DevOps #SoftwareSupplyChain #InfoQ