pub const RESIGN_EVENTS: [&str; 1];Expand description
The events the Dependabot re-sign needs (§9, “Dependabot re-sign bot”):
push, the signed record of who moved each dependabot/* branch, from
which the bridge decides whether a branch is Dependabot’s alone. GitHub
delivers it under Contents, which the App already holds (write, for the
bootstrap commit and the re-signed push). An App registered before push
was in the manifest sees no pushes, so no branch is ever clean and nothing
is re-signed until the owner subscribes it — failing safe.