jbampton opened a new pull request, #263:
URL: https://github.com/apache/shiro-site/pull/263

   Enforces security best practices by requiring a minimum age for new 
dependency releases before they are automatically updated by Dependabot.
   
   This practice, known as a "cooldown period," helps mitigate supply chain 
attacks by allowing time for frequently published malicious packages to be 
identified.
   
   
https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference#cooldown-
   
   
   refs https://github.com/apache/cloudstack/pull/12384


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to