Dependabot version updates introduce default package cooldown
UpdateVerifiedAdded Sep 22, 2026
Dependabot now waits until a new release has been available on its registry for at least three days before opening a version update pull request. This cooldown is now the default and requires no configuration.
Topics: Security, Observability
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Jul 14 | Code scanning shows AI security detections on pull requests Update | Update |
| Jul 15 | Improvements to secret scanning and public monitoring Update | Update |
| Jul 13 | Manage secret scanning custom patterns via REST API GA | GA |
| Jul 13 | GitHub Code Quality license estimate in public preview Preview | Preview |
| Jul 10 | CodeQL 2.26.0 adds Kotlin 2.4.0 support and AI prompt injection detection Update | Update |
| Jul 10 | Clearer names for secret scanning detector types Update | Update |
| Jul 9 | Organization-level targeting for GitHub Code Quality Preview | Preview |
| Jul 20 | GitHub Code Quality is now generally available GA | GA |