chore: remove dependabot version-update config

Drops .github/dependabot.yml, which existed solely to opt into routine
version updates. Dependabot alerts and security updates are repo-level
settings and both stay enabled, so vulnerabilities are still reported and
still get automated fix PRs.

What stops: weekly npm bumps and monthly GitHub Actions bumps. Non-vulnerable
dependencies now drift until a security advisory forces the issue.

Original config recoverable from 30670c8.
This commit is contained in:
tiennm99 committed 2026-07-25 12:14:11 +07:00
1 parent 45237e174f
commit 759adcf876
1 file changed
-19
-19
View File
@@ -1,19 +0,0 @@
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
open-pull-requests-limit: 10
groups:
minor-and-patch:
update-types: ["minor", "patch"]
security:
applies-to: security-updates
patterns: ["*"]
versioning-strategy: increase
labels: ["dependencies", "security"]
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "monthly"