Skip to content

fix(NOJIRA-1234): correct dependabot cooldown configuration#160

Merged
Thr44 merged 1 commit intomainfrom
appsec/fix-dependabot-schema-global
Apr 28, 2026
Merged

fix(NOJIRA-1234): correct dependabot cooldown configuration#160
Thr44 merged 1 commit intomainfrom
appsec/fix-dependabot-schema-global

Conversation

@tf-seti
Copy link
Copy Markdown
Contributor

@tf-seti tf-seti commented Apr 28, 2026

Dependabot Configuration Repair

This automated PR fixes an invalid schema for the cooldown property in dependabot.yml.
The previous configuration used an unsupported nested structure (default: days: 7) which prevented Dependabot from parsing the file correctly.

Changes

  • Updated cooldown to use the official default-days: 7 schema.
  • Maintained exclusions for @typeform/* packages.
  • Verified semantic-release version pins.

Automated by Application Security · global-cooldown-repair

Created by Sourcegraph batch change david.salvador/fix-dependabot-cooldown-global.

@tf-seti tf-seti requested a review from a team as a code owner April 28, 2026 13:19
@pr-auditor
Copy link
Copy Markdown

pr-auditor Bot commented Apr 28, 2026

✅ Security Analysis Results

Great news! No security issues found in this pull request.

Analysis Summary:

  • 📁 Files reviewed: 1
  • ✅ No security vulnerabilities detected

Security analysis powered by Claude Sonnet 4.6 via pr-auditor | Questions? Contact #dx-team or check out this page

@gitstream-cm
Copy link
Copy Markdown

gitstream-cm Bot commented Apr 28, 2026

🥷 Code experts: robespmun

robespmun has most 👩‍💻 activity in the files.
robespmun has most 🧠 knowledge in the files.

See details

.github/dependabot.yml

Activity based on git-commit:

robespmun
APR
MAR
FEB
JAN
DEC
NOV

Knowledge based on git-blame:
robespmun: 16%

✨ Comment /gs review for LinearB AI review. Learn how to automate it here.

@tf-seti tf-seti changed the title fix: correct dependabot cooldown configuration fix(NOJIRA-1234): correct dependabot cooldown configuration Apr 28, 2026
@sonarqubecloud
Copy link
Copy Markdown

@Thr44 Thr44 merged commit bf265d2 into main Apr 28, 2026
13 checks passed
@Thr44 Thr44 deleted the appsec/fix-dependabot-schema-global branch April 28, 2026 13:33
@typeform-ops-gha
Copy link
Copy Markdown

🎉 This PR is included in version 2.10.4 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants