.github: dependabot: wait a week before proposing action updates

Actions are pinned to a tag rather than a commit hash, so a compromised
release reaches whoever updates first; a cooldown gives a bad release
time to be pulled before dependabot offers it.

This is also the one medium zizmor finding in .github/, so it has to be
answered for the lint job to scan the whole directory.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Pierre Kancir
2026-09-22 13:56:23 +10:00
committed by Peter Barker
co-authored by Claude Opus 5
parent dd4e685f5a
commit 0c3072c466
+5
View File
@@ -13,3 +13,8 @@ updates:
- "*" # Group all Actions updates into a single larger pull request
schedule:
interval: weekly
# actions are pinned to a tag rather than a commit hash, so a compromised
# release would be picked up by whoever updates first; wait a week before
# proposing a new version so a bad one has time to be pulled
cooldown:
default-days: 7