Now that our dependencies are up-to-date, run dependabot only once per month, and also ignore patch releases, in order to avoid frequent PRs that all require a review by us.