Dependabot opened major bumps that are real migrations, not safe auto-merges. Tracking them so they're done deliberately with proper testing instead of merged red or left rotting.
Each should be a hand-authored PR with its own testing, superseding the dependabot auto-PR. The dependabot PRs stay open as version pointers but must not be merged as-is.
Dependabot opened major bumps that are real migrations, not safe auto-merges. Tracking them so they're done deliberately with proper testing instead of merged red or left rotting.
Each should be a hand-authored PR with its own testing, superseding the dependabot auto-PR. The dependabot PRs stay open as version pointers but must not be merged as-is.