AI 中文总结
本研究探索了开源 GitHub 项目对 Dependabot 冷却期的采用情况,发现早期采用者多出于安全动机,且偏好简单的默认延迟(如七天),而非细粒度控制,建议工具提供稳健默认值。
AI 中文摘要
自动化依赖更新可能在维护者和更广泛的社区有足够时间检测之前,迅速传播恶意软件包发布。2025年7月,GitHub 将 Dependabot 冷却期作为针对软件供应链攻击的防御措施全面推出。然而,其早期采用的影响仍然未知。在这项探索性研究中,我们实证考察了流行的开源 GitHub 仓库如何采用和配置该功能,并调查了他们的动机。我们发现,在92个已知动机的采用事件中,有83个是出于安全考虑。安全 linter 警告触发了75个仅安全采用中的43个。在保留冷却期的仓库内的251个生态系统中,97.2%设置了通用延迟。其中,64.3%使用了七天,而每种更新类型设置的使用率均低于10%。因此,早期采用者倾向于简单的默认延迟,而非细粒度控制。这些发现表明,工具可以提供反映生态系统支持的稳健默认值,并将细粒度控制保留给具有明确更新优先级的依赖项。
英文摘要
Automated dependency updates can rapidly propagate malicious package releases before maintainers and the broader community have enough time to detect them. In July 2025, GitHub made Dependabot cooldown generally available as a defense against software supply chain attacks. However, the effects of its early adoption remain unknown. In this exploratory study, we empirically examine how popular open-source GitHub repositories adopt and configure the feature and investigate their motivations. We find that security concerns motivated 83 of 92 adoption events with known motivations. Security linter warnings triggered 43 of 75 security-only adoptions. Among 251 ecosystems within repositories that retained cooldown, 97.2% set a general delay. Of these, 64.3% used seven days, while use of each update type setting was below 10%. Early adopters therefore favor simple default delays over fine-grained controls. These findings suggest that tools could provide robust defaults reflecting ecosystem support and reserve fine-grained controls for dependencies with clear update priorities.
Comments32 pages, 11 tables, 2 figures