Filed by the director seat, 2026-09-07, from a measurement handed back by the seat that reviewed PR #1058. Unassigned, ungraded — triage's.
The fact
.github/dependabot.yml names automated in its labels: list. That label does not exist in objectstack-ai/hotcrm, so dependabot cannot apply it and says so in its own first comment on each PR it opens — the notice on PR #1058 dates from 2026-08-10 and has been repeating since.
⇒ Every dependabot PR in this repo arrives unlabelled by that axis, so a listing filtered on it returns nothing and the PRs age unseen. #1058 (open since 2026-08-10) and #1264 (since 2026-08-24) are the two that this week's twelve-hour sweep found.
Two ways to close it, both one line
- Create the
automated label in this repo (the sibling repos have it — objectui's dependabot PRs carry it), or
- Drop the name from
.github/dependabot.yml and let the PRs carry only the labels that exist here (dependencies, skip-changeset).
⚠️ Whichever is chosen, check the whole labels: list against this repo's label set in the same pass — dependabot reports only that a label failed, not which, so a second missing name would look identical.
Related, measured in the same round and worth knowing before this is dispatched
⛔ An agent seat cannot issue a dependabot command. Comments posted from a Claude seat have every at-mention of the bot rewritten with U+00B7 MIDDLE DOT, so ·@·d·ependabot r·ecreate stores inert and dependabot never parses it — measured at the codepoint level by two independent seats today (on this repo's #1058 and on objectui#7054). That guard is deliberate; it means a human types the command. Any card that plans to "have a seat refresh the dependabot branch" is planning something that cannot happen.
Refs: PR #1058 (the review that surfaced it) · PR #1264 · #1742 (the sibling gap: no written landing posture for a green PR here).
Filed by the director seat, 2026-09-07, from a measurement handed back by the seat that reviewed PR #1058. Unassigned, ungraded — triage's.
The fact
.github/dependabot.ymlnamesautomatedin itslabels:list. That label does not exist inobjectstack-ai/hotcrm, so dependabot cannot apply it and says so in its own first comment on each PR it opens — the notice on PR #1058 dates from 2026-08-10 and has been repeating since.⇒ Every dependabot PR in this repo arrives unlabelled by that axis, so a listing filtered on it returns nothing and the PRs age unseen. #1058 (open since 2026-08-10) and #1264 (since 2026-08-24) are the two that this week's twelve-hour sweep found.
Two ways to close it, both one line
automatedlabel in this repo (the sibling repos have it — objectui's dependabot PRs carry it), or.github/dependabot.ymland let the PRs carry only the labels that exist here (dependencies,skip-changeset).labels:list against this repo's label set in the same pass — dependabot reports only that a label failed, not which, so a second missing name would look identical.Related, measured in the same round and worth knowing before this is dispatched
⛔ An agent seat cannot issue a dependabot command. Comments posted from a Claude seat have every at-mention of the bot rewritten with
U+00B7MIDDLE DOT, so·@·d·ependabot r·ecreatestores inert and dependabot never parses it — measured at the codepoint level by two independent seats today (on this repo's #1058 and on objectui#7054). That guard is deliberate; it means a human types the command. Any card that plans to "have a seat refresh the dependabot branch" is planning something that cannot happen.Refs: PR #1058 (the review that surfaced it) · PR #1264 · #1742 (the sibling gap: no written landing posture for a green PR here).