What
The attribution setting can now be a simple true or false value instead of only a group of fields:
falsehides all attribution. It is the same as{ "commit": "", "pr": "", "sessionUrl": false }.trueis the same as leaving the setting out.
An invalid value now produces its own error message. When attribution is false, merging settings from different places forces attribution.sessionUrl to false. The check for whether your settings configure attribution now counts attribution: false too, not only the object form or the deprecated includeCoAuthoredBy.
Why
You can turn off every kind of attribution with one value instead of spelling out each field. A session link cannot slip back in from another settings file.