Drops .github/dependabot.yml, which existed solely to opt into routine
version updates. Dependabot alerts and security updates are repo-level
settings and both stay enabled, so vulnerabilities are still reported and
still get automated fix PRs.
What stops: weekly npm bumps and monthly GitHub Actions bumps. Non-vulnerable
dependencies now drift until a security advisory forces the issue.
Original config recoverable from 30670c8.
LoLdle-style League of Legends daily champion guessing game — SvelteKit web app, Go data scraper, and Android stub in one repo; champion data auto-updates weekly