Disable scheduled version-update PRs (open-pull-requests-limit: 0). Keep grouped security PRs per ecosystem; symphonia migration ignores unchanged.
Document private vulnerability reporting and enable weekly npm/Cargo dependency update PRs; link CONTRIBUTING to the new security policy.