Skip to content

VLN-1347: remediate missing-dependency-cooldown#750

Open
picatz wants to merge 1 commit into
masterfrom
camper/missing-dependency-cooldown-finding-cooldown-sdk-php
Open

VLN-1347: remediate missing-dependency-cooldown#750
picatz wants to merge 1 commit into
masterfrom
camper/missing-dependency-cooldown-finding-cooldown-sdk-php

Conversation

@picatz
Copy link
Copy Markdown

@picatz picatz commented May 15, 2026

🏕️ This pull request was created by camper, an automated security campaign tool.

Finding

Rulemissing-dependency-cooldown
SeverityHIGH
Repositorytemporalio/sdk-php
TicketVLN-1347

Summary

  • .github/dependabot.yml: Added Dependabot configuration with composer and github-actions update entries, each set to schedule.interval: weekly and cooldown.default-days: 14 to enforce a 14-day dependency release age policy.

Instructions

  • Approve to merge this fix
  • Request changes to trigger a new remediation attempt
  • /camper rebase — rebase onto the base branch
  • /camper close — close this PR without merging
  • /camper retry — close and retry with a new fix

@picatz picatz requested review from a team, roxblnfk and wolfy-j as code owners May 15, 2026 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant