Closes #58.
A daemon worker reads the manifests on an opted-in repository's default branch, asks the ecosystem registry for the current release, and maintains one issue per repository: opened when something falls behind, rewritten when the set changes, closed when nothing is behind. No package manager runs, so it needs no runner and no per-repo configuration.
Opt-in and default off: checking a private repository tells a public registry
what it depends on. repo deps enable|disable|status, plus a toggle on the
repository settings page that dispatches the same commands.
Ecosystems: go.mod via proxy.golang.org, package.json with package-lock.json via npm, Cargo.toml with Cargo.lock via crates.io, requirements.txt and pyproject.toml via PyPI. Lockfiles win where present. A requirement naming a set rather than a release is skipped.
Issues are authored by a new keyless gitbay-bot account, added in migration
0028 and reserved in policy/names.go, so the existing notification mail
reaches the owner rather than the actor.
Known limits: root manifests only, so a monorepo with manifests in subdirectories is not scanned; more than 300 direct dependencies has the tail dropped; a Go module with no tags is skipped rather than suggested.
MR generation is deliberately not here — see #58 for why.
The Parity wiki page needs a row for this. CHANGELOG entry belongs with the
release, not this branch.