# GitHub Introduces 3-Day Dependabot Cooldown to Curb Poisoned Packages

GitHub has implemented a mandatory 3-day cooldown period for Dependabot security updates to slow the automatic adoption of potentially malicious packages. The feature aims to give security researchers and maintainers more time to detect and respond to supply chain attacks. This change matters because it addresses the growing risk of compromised dependencies being quickly integrated into thousands of projects.

**Importance:** 3/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/07/github-adds-3-day-dependabot-cooldown.html) — Mon, 27 Jul 2026 13:31:23 +0530