ci: remove the Dependabot configuration - #457
Merged
Merged
Conversation
Dependency updates now come from a single Claude routine, which keeps one dependency pull request per repository. Dependabot alerts stay on, so GitHub Security still reports vulnerabilities. Dependabot no longer opens version update pull requests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ByzsghFd9sFtgiXeU31kZZ
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves:
Description
Before this PR, Dependabot and a Claude routine could both update dependencies, which produced overlapping pull requests.
After this PR, Dependabot opens no version update pull requests. One Claude routine keeps a single dependency pull request, from
claude/dependencies, and lists anything it cannot update in a "Dependency decisions" issue.Dependabot alerts stay on, so GitHub Security still reports vulnerabilities. Dependabot security updates are a repository setting and are turned off separately.
Checklist
Preview
How to QA 1
🤖 Generated with Claude Code
https://claude.ai/code/session_01ByzsghFd9sFtgiXeU31kZZ
Generated by Claude Code
Note
Low Risk
Repository automation only—no runtime or dependency resolution logic changes; security alerting remains enabled per the PR description.
Overview
Removes automated Dependabot version-update PRs by deleting
.github/dependabot.yml, which had weekly npm scans, grouped security/minor-patch/major updates, and an ignore rule for major bumps of@prismicio/types-internal.Dependency bumps are expected to come from the existing Claude routine on
claude/dependenciesinstead, so two bots no longer open competing update PRs. Dependabot vulnerability alerts are unchanged; only the config-driven version-update workflow is gone.Reviewed by Cursor Bugbot for commit 590b0c0. Bugbot is set up for automated code reviews on this repo. Configure here.
Footnotes
Please use these labels when submitting a review:
⚠️ #issue: Strongly suggest a change.
❓ #ask: Ask a question.
💡 #idea: Suggest an idea.
🎉 #nice: Share a compliment. ↩