Commit aa21de8
chore: remove dependabot in favor of weekly batch dependency updates [RED-695] (#1395)
Dependabot opened up to 3 npm version-update PRs daily, duplicating the weekly
batched dependency update that is Node-floor aware and respects the
minimumReleaseAge embargo in pnpm-workspace.yaml. Its output was already being
discarded: the five most recent Dependabot PRs were closed rather than merged.
Dependabot's version updates were the only remaining producer of the
`dependencies` label, so the `Improvements` category that mapped it in
.github/release.yml is removed too, along with the `dependencies` exclusion
under `Other Changes`. Weekly batch PRs are unlabeled and already fall into
`Other Changes`, so generated release notes are unaffected in practice.
Dependabot security alerts and security updates are a repository setting rather
than a function of this config and remain enabled. Should a security-update PR
be opened and merged, it carries the `dependencies` label and is now grouped
under `Other Changes`.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>1 parent cf60e7e commit aa21de8
2 files changed
Lines changed: 0 additions & 19 deletions
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
0 commit comments