Skip to content

Commit d06c030

Browse files
committed
Note that Dependabot cooldown for Docker only covers Docker Hub images
1 parent 18945a3 commit d06c030

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

‎content/code-security/reference/supply-chain-security/dependabot-options-reference.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -289,6 +289,7 @@ The table below shows the package managers that support `cooldown`. The `default
289289
>
290290
> * If `semver-major-days`, `semver-minor-days`, or `semver-patch-days` are not defined, the `default-days` settings will take precedence for cooldown-based updates.
291291
> * The `exclude` list always take precedence over the `include` list. If a dependency is specified in both lists, it is **excluded from cooldown** and will be updated immediately.
292+
> * For Docker and Docker Compose, the cooldown only applies to images on Docker Hub, the only registry {% data variables.product.prodname_dependabot %} reads a publication date from. For images in other registries, such as the {% data variables.product.prodname_container_registry %}, {% data variables.product.prodname_dependabot %} skips the cooldown and proposes the newest tag right away, with a note in the pull request that the cooldown could not be applied.
292293

293294
{% endif %}
294295

0 commit comments

Comments
 (0)