#GitHub's Dependabot now waits 3 days by default before opening pull requests for new non-security dependency versions.
The delay gives security scanners and the community more time to detect and remove malicious releases before they're integrated into projects.
Read the full story on InfoQ 👉 https://bit.ly/4xeUgVY
Comments (0)