Tag
GitHub's Dependabot now defaults to a three-day cooldown before opening version update pull requests, requiring no configuration.
Dependabot now waits three days before opening version update PRs to reduce risk of supply chain attacks. Security updates remain immediate.
The author details how their OpenClaw agent, Francis, automated a massive backlog of Dependabot security fixes on an open-source project, recovering from session failures and ultimately cleaning the audit, proving the practical value of their agentic setup.