mirror of
https://github.com/loot/libloot.git
synced 2026-07-27 14:16:01 -07:00
So that Dependabot won't open PRs for updates that are less than 7 days old, to reduce the risk of getting caught up in supply chain attacks. The use of cargo-vet already prevents CI builds from passing with un-vetted dependency versions, but this should save a little effort for Python and Node.js dependencies. Cooldowns aren't supported for GitHub Actions dependencies.