chore(dependabot): remove the Dependabot configuration - #63
Conversation
Renovate is the dependency-update tool for this organization, and it is live in this repository -- Dependency Dashboard #16. Dependabot duplicated it here: both bots opened a pull request for the same update, and whichever merged first left the other to be closed. The removed file declared: composer,github-actions Renovate currently detects: .pre-commit-config.yaml,composer,composer.json,github-actions,npm,package.json,pre-commit So nothing loses coverage. Renovate also carries the policy the Dependabot block never had: stability days, the automerge rules and the deps-no-automerge label all come from github>netresearch/renovate-config. Dependabot SECURITY updates are unaffected. Those are a repository setting, not this file, and they stay on. Assisted-by: claude-code:claude-opus-5 Agent-Session: https://claude.ai/code/session_01AXRGd6GWAC7TLK3wuiYeGg Agent-Host: 0493f0 Signed-off-by: Sebastian Mendel <info@sebastianmendel.de>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
💤 Files with no reviewable changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe pull request deletes Merge Risk: ⚪ Minimal · up to Removing the redundant configuration should preserve dependency-update coverage through Renovate without introducing a merge-blocking production risk. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
|
Self-review: 6b7a156 The review this pull request demands is unsatisfiable (Copilot quota wall or repeated bot failures on this head). Per the documented fallback, the diff on this head was reviewed by the PR author; this comment is the on-the-record attestation the merge gate reads back. It stops matching on the next push. |



Renovate is the dependency-update tool for this organization and it is live here — Dependency Dashboard #16. Dependabot duplicated it: both bots opened a pull request for the same update, and whichever merged first left the other to be closed or auto-closed, costing CI minutes and review attention twice.
Nothing loses coverage. Measured on this repository rather than assumed:
.github/dependabot.ymldeclared:composer,github-actions.pre-commit-config.yaml,composer,composer.json,github-actions,npm,package.json,pre-commitRenovate also carries the policy the Dependabot block never had — stability days, the automerge rules and the
deps-no-automergelabel all come fromgithub>netresearch/renovate-config.Dependabot security updates are unaffected. Those are a repository setting, not this file, and they stay on.
Part of a fleet-wide sweep for netresearch/.github#410, applied to the 78 non-mirror repositories where Renovate is demonstrably running and covers every ecosystem Dependabot declared. Two repositories were deliberately excluded because Renovate does not currently see an ecosystem Dependabot does:
ldap-manager(gomod) andnode-agent-skill-coordinator(github-actions).Assisted by claude-code:claude-opus-5 — Session