• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

sirbrillig / phpcs-variable-analysis / 32164476515
94%
2.x: 94%

Build:
Build:
LAST BUILD BRANCH: feature/ghactions-set-minimal-permissions
DEFAULT BRANCH: 2.x
Ran 18 Aug 2026 05:15PM UTC
Jobs 4
Files 9
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

18 Aug 2026 05:12PM UTC coverage: 94.489%. Remained the same
32164476515

push

github

jrfnl
Dependabot: add cooldown period

Updating all dependencies immediately after release carries risks as the package may have been compromised. The package may also still have "teething problems", especially for new features.
Aside from known security releases, waiting a few days/weeks is often the less risky option, in hopes that someone else find a potential problems before we update the package.
This is called a "cooldown" period.

Or as Zizmor describes it:
> Performing updates without an appropriate cooldown presents both stability and supply-chain security risks:
> * **Stability**: updating to the newest version of a dependency immediately after its release increases the risk of breakage, since new releases may contain regressions or other issues that other users have not yet discovered.
> * **Supply-chain security**: package compromises are frequently _opportunistic_, meaning that the attacker expects to have their compromised version taken down by the packaging ecosystem relatively quickly. Updating immediately to a newly released version increases the risk of automatically pulling in a compromised version before it can be taken down.

Of course, for frequently released packages, this `cooldown` period shouldn't be too long, as otherwise the package will never update, as the "latest" release will always be too young.

Since July 2025, the Dependabot config offers the possibility to add a `cooldown` period to delay the creation of dependency update PRs based on the number days since the release came out.
Depending on the ecosystem, this `cooldown` period can be configured with more or less flexibility (only `default-days` or semver based differentiation). _Unfortunately, the `github-actions` ecosystem only allows the `default-days` option._

Since then (July 2026), GitHub, in their wisdom, has introduced a standard "cooldown" period for all packages of three days.
This is counter-productive as that means that the chances of a compromise being foun... (continued)

1749 of 1851 relevant lines covered (94.49%)

138.7 hits per line

Jobs
ID Job ID Ran Files Coverage
1 php-7.4-phpcs-3.13.6 - 32164476515.1 18 Aug 2026 05:15PM UTC 9
93.8
GitHub Action Run
2 php-8.5-phpcs-4.x-dev - 32164476515.2 18 Aug 2026 05:15PM UTC 9
93.98
GitHub Action Run
3 php-7.2-phpcs-4.x-dev - 32164476515.3 18 Aug 2026 05:15PM UTC 9
92.83
GitHub Action Run
4 php-5.4-phpcs-3.13.6 - 32164476515.4 18 Aug 2026 05:16PM UTC 9
93.5
GitHub Action Run
Source Files on build 32164476515
  • Tree
  • List 9
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #32164476515
  • bc06450c on github
  • Prev Build on trunk (#32146246472)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc