#1257: WG Revision:

Visit on Github

Opened Aug 11, 2026

Specification

https://Gallery Lock all video active

Explainer

https://# Dependabot update pull requests no longer generated Dependabot can pause updates based on your interaction with Dependabot pull requests. Learn more about the automatic deactivation of Dependabot updates. * When maintainers of a repository stop interacting with Dependabot pull requests, Dependabot temporarily pauses its updates and lets you know. * Dependabot stops rebasing pull requests for version and security updates after 30 days, reducing notifications for inactive Dependabot pull requests. ## About automatic deactivation of Dependabot updates Dependabot pauses updates on your repositories, based on your interaction with pull requests from Dependabot updates. When Dependabot automatically deactivates Dependabot updates, there is: * No creation of pull requests for version and security updates. * No rebasing of Dependabot pull requests for inactive repositories. >[!NOTE] The automatic deactivation of Dependabot updates only applies to repositories where Dependabot has opened pull requests but the pull requests remain untouched. If Dependabot hasn't opened any pull requests, Dependabot will never become paused. An active repository is a repository where a user (not Dependabot) has taken any of the following actions in the last 90 days: * Merged or closed a Dependabot pull request on the repository. * Made a change to the dependabot.yml file for the repository. * Manually triggered a security update or a version update. * Enabled Dependabot security updates for the repository. * Used @dependabot commands on pull requests. An inactive repository is a repository: * That has at least one Dependabot pull request open for more than 90 days, * That has been enabled for the full period, and * Where none of the actions listed above has been taken by a user. ## How to know if Dependabot updates are paused When Dependabot is paused, GitHub adds a banner notice: * To all open Dependabot pull requests. * To the UI of the Settings tab of the repository (under Advanced Security, then Dependabot). * To the list of Dependabot alerts (if Dependabot security updates are affected). ## About automatic reactivation of Dependabot updates As soon as someone interacts with a Dependabot pull request again, Dependabot will unpause itself: * Security updates are automatically resumed for Dependabot alerts. * Version updates are automatically resumed with the schedule specified in the dependabot.yml file.

Links

  • The WG's request for this TAG review: https:// <!-- Usually a deep link into minutes or an email thread. -->
  • TAG review of the previous version of this specification, if any: https://github.com/w3ctag/design-reviews/issues/####
  • A description of what has changed since our previous review: https://...#section
<!-- Make a copy of the below items for each distinct feature that has changed since our previous reviewed , and fill in links to describe that feature. For small changes, these may all be interesting in the issue that motivated the change, but please double-check that all the answers are actually there. -->

Feature 1:

  • Previous early design review, if any: https://github.com/w3ctag/design-reviews/issues/####
  • An introduction to the feature, aimed at unfamiliar audiences: https:// <!-- Can be the specification's or explainer's introduction, or another section. -->
  • A description of the problems that end-users were facing before this proposal: https:// <!-- See https://w3ctag.github.io/explainer-explainer/#end-user-need -->
  • Alternatives considered: https:// <!-- See https://w3ctag.github.io/explainer-explainer/#alternatives -->
  • Examples of how to use the proposal to solve the end-users' problems: https:// <!-- See https://w3ctag.github.io/explainer-explainer/#describe-proposal -->
  • What do the end-users experience with this proposal: https:// <!-- See https://w3ctag.github.io/explainer-explainer/#describe-proposal -->
  • User research you did to validate the problem and/or design, if any: https://
  • Web Platform Tests: <!-- Or other tests if this is not a web platform feature. -->

The specification

Where and by whom is the work is being done?

  • GitHub repo:
  • Primary contacts:
    • $name (@-mention), $organization/s, $role in developing specification
    • <!-- repeat as necessary, we recommend including group chairs and editors in this list -->
  • Organization/project driving the specification:
  • This work is being funded by:
  • Primary standards group developing this feature:
  • Incubation and standards groups that have discussed the design:
    • {{ABC CG}} <!-- Include a link to minutes or issues in this group if possible. -->
    • {{DEF WG}}

Feedback so far

  • Active horizontal reviews: https:// <!-- Link to an issue like https://github.com/webmachinelearning/webnn/issues/239, https://github.com/WebAssembly/spec/issues/1804, or https://github.com/w3c/did/issues/885, which itself links to the other horizontal reviews. If you haven't started the rest of the horizontal reviews, please consider doing so. -->
  • Multi-stakeholder feedback:
  • Major unresolved issues with or opposition to this specification:
  • Status/issue trackers for implementations: <!-- Include links to [Chrome Status](https://chromestatus.com/), [Mozilla's](https://bugzilla.mozilla.org/), [WebKit's Bugzilla](https://bugs.webkit.org/), and trackers for other implementations if those are known to you. -->

You should also know that...

No response

<!-- Content below this is maintained by @w3c-tag-bot -->

Track conversations at https://tag-github-bot.w3.org/gh/w3ctag/design-reviews/1257

Discussions