Split empty-plugin into a truly generic one (no scm section or url); and then add a new (empty) archetype specifically for @jenkinsci-hosted plugins where we can preconfigure things like
to follow current best practices.
W.r.t. Dependabot, it indeed requires JENKINS-47498 to be sustainable