From 2368daa9e3ea36c3d2d43277e8a10350ac358778 Mon Sep 17 00:00:00 2001 From: moezein0 <169095174+moezein0@users.noreply.github.com> Date: Tue, 24 Mar 2026 16:15:02 -0400 Subject: [PATCH 1/2] chore: disable automated dependency updater config [incident-51602] --- .github/dependabot.yml | 37 ------------------------------------- 1 file changed, 37 deletions(-) delete mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml deleted file mode 100644 index 080754b656d..00000000000 --- a/.github/dependabot.yml +++ /dev/null @@ -1,37 +0,0 @@ -# To get started with Dependabot version updates, you'll need to specify which -# package ecosystems to update and where the package manifests are located. -# Please see the documentation for all configuration options: -# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file - -version: 2 -updates: - - package-ecosystem: "github-actions" - directory: "/" - schedule: - interval: "weekly" - labels: - - "comp: tooling" - - "tag: dependencies" - - "tag: no release notes" - commit-message: - prefix: "chore(ci): " - groups: - gh-actions-packages: - patterns: - - "*" - - - package-ecosystem: "gradle" - directory: "/" - schedule: - interval: "weekly" - allow: - - dependency-name: "gradle" - ignore: - - dependency-name: "gradle" - update-types: ["version-update:semver-major"] - labels: - - "comp: tooling" - - "tag: dependencies" - - "tag: no release notes" - commit-message: - prefix: "chore(build): " From 6c83a1837dd2efbfa0e475e8f63b063f99fd6045 Mon Sep 17 00:00:00 2001 From: moezein0 <169095174+moezein0@users.noreply.github.com> Date: Tue, 24 Mar 2026 16:15:03 -0400 Subject: [PATCH 2/2] chore: disable automated dependency updater config [incident-51602] --- .github/dependabot.yml.disabled | 37 +++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 .github/dependabot.yml.disabled diff --git a/.github/dependabot.yml.disabled b/.github/dependabot.yml.disabled new file mode 100644 index 00000000000..080754b656d --- /dev/null +++ b/.github/dependabot.yml.disabled @@ -0,0 +1,37 @@ +# To get started with Dependabot version updates, you'll need to specify which +# package ecosystems to update and where the package manifests are located. +# Please see the documentation for all configuration options: +# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file + +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + labels: + - "comp: tooling" + - "tag: dependencies" + - "tag: no release notes" + commit-message: + prefix: "chore(ci): " + groups: + gh-actions-packages: + patterns: + - "*" + + - package-ecosystem: "gradle" + directory: "/" + schedule: + interval: "weekly" + allow: + - dependency-name: "gradle" + ignore: + - dependency-name: "gradle" + update-types: ["version-update:semver-major"] + labels: + - "comp: tooling" + - "tag: dependencies" + - "tag: no release notes" + commit-message: + prefix: "chore(build): "