[skip changelog] Remove obsolete "Dependabot Preview" configuration file #1372
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Please check if the PR fulfills these requirements
before creating one)
our contributing guidelines
UPGRADING.md
has been updated with a migration guide (for breaking changes)Infrastructure cleanup.
Dependabot Preview shut down 2021-08-03:
https://github.blog/changelog/2021-08-03-dependabot-preview-is-shutting-down/
It is replaced by GitHub-native Dependabot, which uses the
.github/dependabot.yml
configuration file, with a different data format.So the
.dependabot/config.yml
file is now completely obsolete and serves no purpose. I might cause confusion and wasted time if a maintainer attempts to use it to configure Dependabot.The repository does not have a worthless Dependabot Preview configuration file.
From an investigation into how the obsolete configuration could be migrated to the new format, I determined that the
specific "security updates only" configuration used by this repository is not provided by the new configuration file, which is for configuring updates of any outdated dependencies. The "security updates" feature is configured via the repository settings (Settings > Security & analysis):
https://docs.github.com/en/code-security/supply-chain-security/managing-vulnerabilities-in-your-projects-dependencies/configuring-dependabot-security-updates
Does this PR introduce a breaking change, and is
titled accordingly?
No breakie