Is there an existing issue for this?
Feature description
There is already an issue for this: #9522 that has been closed, but I've confirmed with GitHub support that in fact it is still not supported for security updates.
We are not seeing any security alerts since upgrading. This seems pretty dangerous given others may also have upgraded without realising they would no longer receive updates - dependabot doesn't seem to trigger any warning for this?