GitHub explains why Dependabot is introducing a delay before issuing version-update pull requests. The change follows a September 2025 npm supply-chain incident in which a phished maintainer account was used to publish poisoned versions of chalk, debug, and roughly a dozen other packages downloaded more than 2 billion times per week. The malicious code rewrote cryptocurrency wallet addresses in browser applications and remained available for about two hours. A cooldown gives maintainers, researchers, and automated scanners time to detect and remove a release before it reaches a team’s update workflow.
No heat snapshots are available in the last 24 hours.