logoalt Hacker News

capitol_today at 9:13 AM0 repliesview on HN

The cooldown setting in dependabot solves this attack vector. By setting it you give security vendors time to scan new packages.