<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dependabot on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/dependabot/</link><description>Recent content in Dependabot on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 29 Jul 2026 12:56:53 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/dependabot/index.xml" rel="self" type="application/rss+xml"/><item><title>Dependabot alerts now cover malicious packages via OpenSSF data</title><link>https://curadevops.metacog.co.kr/insights/2026-07-29-dependabot-alerts-on-malicious-packages-across-more-ecosyste/</link><pubDate>Wed, 29 Jul 2026 12:56:53 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-29-dependabot-alerts-on-malicious-packages-across-more-ecosyste/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> Enable or verify Dependabot alerts are active across your repos to benefit from the expanded OpenSSF malicious-package coverage; no deadline, but this materially improves supply-chain detection in your dependency pipeline.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Broader malware signal coverage from OpenSSF integration strengthens your software supply-chain posture — confirm Dependabot alerts are enabled org-wide as a policy standard this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Dependabot adds 3-day cooldown before opening version update PRs</title><link>https://curadevops.metacog.co.kr/insights/2026-07-15-dependabot-version-updates-introduce-default-package-cooldow/</link><pubDate>Wed, 15 Jul 2026 12:10:55 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-15-dependabot-version-updates-introduce-default-package-cooldow/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Dependabot&amp;rsquo;s new default 3-day cooldown before raising version-update PRs reduces noise from yanked or quickly-patched releases; no pipeline changes required, but worth understanding if teams rely on same-day dependency PRs.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>