<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Software Supply Chain - News</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Software Supply Chain News feed</description>
    <item>
      <title>GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates</title>
      <link>https://www.infoq.com/news/2026/07/github-dependabot-cooldown/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Software+Supply+Chain-news</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;Instead of immediately opening pull requests when newer dependency versions are released, Dependabot now waits three days before suggesting upgrades, thus increasing the likelihood that malicious releases are identified and removed before they can be integrated.&lt;/p&gt; &lt;i&gt;By Sergio De Simone&lt;/i&gt;</description>
      <category>github</category>
      <category>Security Vulnerabilities</category>
      <category>Software Supply Chain</category>
      <category>Dependency Management</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Tue, 28 Jul 2026 19:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/07/github-dependabot-cooldown/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Software+Supply+Chain-news</guid>
      <dc:creator>Sergio De Simone</dc:creator>
      <dc:date>2026-07-28T19:00:00Z</dc:date>
      <dc:identifier>/news/2026/07/github-dependabot-cooldown/en</dc:identifier>
    </item>
  </channel>
</rss>
