<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Dependency Management</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Dependency Management feed</description>
    <item>
      <title>GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates</title>
      <link>https://www.infoq.com/news/2026/07/github-dependabot-cooldown/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Dependency+Management</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;Instead of immediately opening pull requests when newer dependency versions are released, Dependabot now waits three days before suggesting upgrades, thus increasing the likelihood that malicious releases are identified and removed before they can be integrated.&lt;/p&gt; &lt;i&gt;By Sergio De Simone&lt;/i&gt;</description>
      <category>Software Supply Chain</category>
      <category>github</category>
      <category>Security Vulnerabilities</category>
      <category>Dependency Management</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Tue, 28 Jul 2026 19:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/07/github-dependabot-cooldown/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Dependency+Management</guid>
      <dc:creator>Sergio De Simone</dc:creator>
      <dc:date>2026-07-28T19:00:00Z</dc:date>
      <dc:identifier>/news/2026/07/github-dependabot-cooldown/en</dc:identifier>
    </item>
    <item>
      <title>GitLab 19.2 Puts AI Agents to Work on the Security Backlog</title>
      <link>https://www.infoq.com/news/2026/07/gitlab-19-2-ai-agents/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Dependency+Management</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/07/gitlab-19-2-ai-agents/en/headerimage/generatedHeaderImage-1784567507763.jpg"/&gt;&lt;p&gt;GitLab has released version 19.2 of its DevSecOps platform, adding agentic automation aimed at the security and review work that has piled up as AI coding tools generate more code than developers can check by hand. The release, announced on 16 July 2026, brings four features out of beta or into public beta: Dependency Scanning Auto-Remediation, Security Review Flow, GitLab Duo CLI and Custom Flows&lt;/p&gt; &lt;i&gt;By Matt Saunders&lt;/i&gt;</description>
      <category>Application Security</category>
      <category>GitLab</category>
      <category>Continuous Integration</category>
      <category>Dependency Management</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Tue, 21 Jul 2026 08:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/07/gitlab-19-2-ai-agents/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Dependency+Management</guid>
      <dc:creator>Matt Saunders</dc:creator>
      <dc:date>2026-07-21T08:00:00Z</dc:date>
      <dc:identifier>/news/2026/07/gitlab-19-2-ai-agents/en</dc:identifier>
    </item>
  </channel>
</rss>
