Research
Early Dependabot Cooldown Adopters Pick One Default Delay and Ignore Fine-Grained Controls
An exploratory study of Dependabot cooldown (arXiv 2609.16605, submitted 15 Sep 2026), the supply-chain defense GitHub made generally available in July 2025, examined adoption in popular open-source repositories. Security concerns motivated 83 of 92 adoption events with known motivations, and security linter warnings triggered 43 of 75 security-only adoptions. Among 251 ecosystems in repositories that retained cooldown, 97.2% set a general delay and 64.3% of those used seven days, with each per-update-type setting used in under 10% of cases, suggesting tools should ship robust defaults instead of fine-grained knobs.
↳ Follow the thread