Skip to content

ci: disable Dependabot (manual upgrades) - #419

Merged
HardlyDifficult merged 1 commit into
mainfrom
agent/remove-dependabot
Sep 23, 2026
Merged

HardlyDifficult merged 1 commit into
mainfrom
agent/remove-dependabot

Conversation

@HardlyDifficult

Copy link
Copy Markdown
Collaborator

Dependabot is being retired on this repo — dependency upgrades move to a manual cadence (see #417 as the model).
Security alerts (Dependabot alerts) remain enabled; only version-bump PRs stop.
This PR deletes only .github/dependabot.yml.

Made with Cursor

@HardlyDifficult
HardlyDifficult marked this pull request as ready for review September 23, 2026 19:25
Copilot AI balanced review requested due to automatic review settings September 23, 2026 19:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused deletion matches the stated intent without affecting Dependabot security alerts.

Review effort: Balanced
Findings: None

What changed in this PR

Removes automated dependency-update PRs in favor of the manual upgrade cadence demonstrated by PR #417.

Changes:

  • Deletes weekly npm and GitHub Actions Dependabot update configuration.
File Description
.github/​dependabot.yml Removes automated dependency version updates.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@HardlyDifficult HardlyDifficult self-assigned this Sep 23, 2026
@HardlyDifficult
HardlyDifficult merged commit 88cd1f1 into main Sep 23, 2026
11 checks passed
@HardlyDifficult
HardlyDifficult deleted the agent/remove-dependabot branch September 23, 2026 20:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants