Renovate Actions PR Review
backnotprop/plannotator
Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.
Review and merge open dependency pull requests from Dependabot, Renovate and similar bots across the goreleaser organization and the caarlos0 user.
$ npx skills add caarlos0/dotfiles --skill dependabot-merge -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install caarlos0/dotfiles dependabot-merge --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/caarlos0/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependabot-merge .claude/skills/dependabot-merge && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependabot-merge" agent skill from https://github.com/caarlos0/dotfiles/tree/main/skills/dependabot-merge into .claude/skills/dependabot-merge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-merge", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/caarlos0/dotfiles/tree/main/skills/dependabot-mergeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add caarlos0/dotfiles --skill dependabot-merge -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install caarlos0/dotfiles dependabot-merge --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/caarlos0/dotfiles.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dependabot-merge .agents/skills/dependabot-merge && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependabot-merge" agent skill from https://github.com/caarlos0/dotfiles/tree/main/skills/dependabot-merge into .agents/skills/dependabot-merge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-merge", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add caarlos0/dotfiles --skill dependabot-merge -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install caarlos0/dotfiles dependabot-merge --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/caarlos0/dotfiles.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dependabot-merge .cursor/skills/dependabot-merge && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependabot-merge" agent skill from https://github.com/caarlos0/dotfiles/tree/main/skills/dependabot-merge into .cursor/skills/dependabot-merge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-merge", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/caarlos0/dotfiles.git --path skills/dependabot-merge--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add caarlos0/dotfiles --skill dependabot-merge -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install caarlos0/dotfiles dependabot-merge --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/caarlos0/dotfiles.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dependabot-merge .gemini/skills/dependabot-merge && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependabot-merge" agent skill from https://github.com/caarlos0/dotfiles/tree/main/skills/dependabot-merge into .gemini/skills/dependabot-merge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-merge", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install caarlos0/dotfiles dependabot-mergeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add caarlos0/dotfiles --skill dependabot-merge -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/caarlos0/dotfiles.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dependabot-merge .github/skills/dependabot-merge && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependabot-merge" agent skill from https://github.com/caarlos0/dotfiles/tree/main/skills/dependabot-merge into .github/skills/dependabot-merge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-merge", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add caarlos0/dotfiles --skill dependabot-merge -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install caarlos0/dotfiles dependabot-merge --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/caarlos0/dotfiles.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dependabot-merge .opencode/skills/dependabot-merge && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependabot-merge" agent skill from https://github.com/caarlos0/dotfiles/tree/main/skills/dependabot-merge into .opencode/skills/dependabot-merge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-merge", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependabot-mergeReview and merge open dependency pull requests from Dependabot, Renovate and similar bots across the goreleaser organization and the caarlos0 user.
Dependabot Merge is an agent skill from caarlos0/dotfiles. Review and merge open dependency pull requests from Dependabot, Renovate and similar bots across the goreleaser organization and the caarlos0 user. Use for dependency update triage, supply-chain checks on bumps, or bulk dependency merges.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management and Pull requests. The licence is MIT.
Read from SKILL.md and the folder at commit 892360f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghcurljqshnpmgoFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
registry.npmjs.orggithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependabot Merge loads about 5k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 2,568 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from caarlos0/dotfiles at commit 892360f, republished under its MIT licence (© caarlos0). 2,568 words, ~4,992 tokens.
.claude/skills/dependabot-merge/SKILL.md (or your agent's skills folder).Merge safe dependency updates. Stop and report the unsafe ones. Never merge a pull request that you did not check in this run.
Use the gh-cli skill for queries, required-check watching, and failure logs.
In a batch, process other ready pull requests instead of waiting on one.
The checks are the same for every dependency bot. Only the discovery query and the place that holds the update metadata change. See "Which bots".
The scope is fixed: the goreleaser organization and the caarlos0
user. Do not ask which owners to process. Start the run immediately.
Never widen the scope on your own. The user belongs to many organizations that they do not maintain. Merging there affects other people. Process another owner only when the user names it in the argument, and process only that owner in addition to the two above.
Keep a ledger, so that a second run does not check the same pull request again.
Create it once per run with the sql tool:
CREATE TABLE IF NOT EXISTS dependabot_prs (
url TEXT PRIMARY KEY,
repo TEXT, number INTEGER, title TEXT,
bot TEXT, -- dependabot | renovate | pre-commit-ci | ...
state TEXT, -- pending | merged | skipped | blocked | failed
reason TEXT,
checked_at TEXT
);Write a row with state='pending' when you find a pull request. Update the row
immediately after each decision. Read the ledger before each step and process
only pending rows. Report the terminal rows again at the end, but do not
check them again.
Handle every dependency bot, not only Dependabot. They differ in three ways: the author login, where the update metadata lives, and the branch prefix.
| Bot | Author login | Metadata lives in | Branch prefix |
|---|---|---|---|
| Dependabot | dependabot[bot] | updated-dependencies: block in the commit body | dependabot/ |
| Renovate | renovate[bot] | a table in the pull request body | renovate/ |
| Mend/self-hosted Renovate | a custom account, often renovate-bot | same as Renovate | renovate/ |
| pre-commit.ci | pre-commit-ci[bot] | the pull request body; edits .pre-commit-config.yaml | pre-commit-ci-update-config |
Renovate has no commit metadata block. Its versions live in a markdown
table in the pull request body, next to a <!--renovate-debug:...--> comment:
gh pr view NUMBER -R REPO --json body -q .bodyThat table is generated at the same time as the diff, but it is still a summary. The rule below does not change: read the diff.
Two Renovate-only things to watch:
renovate.json, .github/renovate.json or
.renovate.json is a configuration change, not a dependency bump. It is
outside the manifest/lockfile/workflow allowlist, so it is blocked for a
human.postUpgradeTasks and custom managers, so it can touch
files a version bump does not explain. Treat any such file as a block.gh search prs takes only one --author, and a second flag silently replaces
the first. Use the search API instead, where a repeated author: qualifier
means OR.
Run one query for each owner. org: covers an organization and user:
covers a personal account; they are not interchangeable, and a separate query
keeps the 100-item page limit and any error for each owner separate. These are
the discovery commands for this skill — run them as-is:
BOTS='is:pr is:open draft:false author:app/dependabot author:app/renovate author:app/pre-commit-ci'
gh api -X GET search/issues -f per_page=100 \
-f q="org:goreleaser $BOTS" \
--jq '.items[] | "\(.user.login)\t\(.html_url)\t\(.title)"'
gh api -X GET search/issues -f per_page=100 \
-f q="user:caarlos0 $BOTS" \
--jq '.items[] | "\(.user.login)\t\(.html_url)\t\(.title)"'Collect both into urls.txt for the parallel fetch below:
for owner in org:goreleaser user:caarlos0; do
gh api -X GET search/issues -f per_page=100 \
-f q="$owner $BOTS" --jq '.items[].html_url'
done > urls.txtEach query returns at most 100 items for each page. Compare the line count
with total_count and paginate with -f page=2 when it is larger.
Keep the q value on one line. A newline inside it makes the search API reject
the whole query with 422 Validation Failed.
Add a self-hosted bot with a plain author:renovate-bot (no app/ prefix,
because it is a normal account).
Do not trust is_bot. In gh search prs output, dependabot[bot] reports
is_bot: false. Match on the login instead.
Insert the results into the ledger, recording which bot opened each one.
Use single quotes for every SQL string. SQLite rejects a double-quoted literal that does not name a column, and the whole insert fails.
Fetch the facts for all of them in parallel, then triage from one table
instead of one round trip per pull request. Write the worker to a file: on
macOS, xargs -I combined with -n 1 and a long inline sh -c fails with
command line cannot be assembled, too long.
cat > fetch.sh <<'EOF'
#!/bin/sh
gh pr view "$1" --json number,url,author,isDraft,mergeable,mergeStateStatus,\
files,commits,statusCheckRollup > "out/$(echo "$1" | tr '/:' '__').json" 2>&1
EOF
chmod +x fetch.sh
xargs -P 8 -I{} ./fetch.sh {} < urls.txtGet the facts in one call:
gh pr view URL --json number,author,isDraft,mergeable,mergeStateStatus,\
reviewDecision,files,commits,statusCheckRollupThe commit body holds the metadata in the updated-dependencies: block:
dependency-name, dependency-version, dependency-type, and update-type.
A grouped update lists many entries. Check every entry. Renovate puts the same
information in the pull request body instead — see "Which bots".
The metadata can disagree with the diff. The diff wins. The bot rebases and
the summary goes stale. One pull request declared
dependency-version: 5.24.0 and update-type: version-update:semver-minor
while gh pr diff showed 5.22.0 to 6.0.0. Another declared
dependency-version: 10.0.1 while the workflow comment still read # v6.6.1
and the real old pin was v8.2.0 — three different answers, and only the diff
was right. Read the diff before you call a bump minor:
gh pr diff NUMBER -R REPO -- package.json go.modFor a pinned action, the comment after the SHA is decoration and can be stale. Resolve the SHA itself:
gh api repos/OWNER/REPO/tags --paginate \
--jq '.[] | select(.commit.sha=="NEWSHA") | .name'Set state='blocked' and continue to the next pull request if any of these is
true:
mergeable is CONFLICTING;uv.lock, flake.lock, Cargo.lock, pnpm-lock.yaml),
or it changes the bot's own configuration;preinstall,
postinstall, prepare).A version-update:semver-major is not an automatic block. See "Major updates".
For an npm bump, compare the maintainer set of both versions, not only the
new one:
for v in OLD NEW; do
curl -s "https://registry.npmjs.org/PKG/$v" | jq -c '[.maintainers[].name]'
doneA set that shrinks inside the bump window is a block. axios went from 4
maintainers to 1 between 1.13.6 and 1.18.0, which concentrates publish rights
on one account.
Separate required failures from advisory ones. mergeStateStatus is an
initial signal, not a complete check result:
| Value | Meaning |
|---|---|
CLEAN | mergeable, nothing red |
UNSTABLE | mergeable; only non-required checks are red — not a blocker |
BEHIND | strict protection, branch out of date |
BLOCKED | required check, missing review, or an archived repository |
UNKNOWN | GitHub is still computing — recheck once, then report unknown |
Use gh pr checks NUMBER -R REPO --required to identify required checks.
If the required set is unclear, confirm with protection and rulesets for the
pull request's actual base branch, not necessarily the default branch:
base=$(gh pr view NUMBER -R REPO --json baseRefName --jq '.baseRefName | @uri')
gh api "repos/REPO/branches/$base/protection" --jq '.required_status_checks.contexts'
gh api "repos/REPO/rules/branches/$base" \
--jq '[.[]|select(.type=="required_status_checks")
|.parameters.required_status_checks[].context]'404 Branch not protected and an empty ruleset list mean nothing is required.
A 403 means you cannot read the rules. If the required set cannot be
established, report it as unknown and block rather than infer passing CI.
Check isArchived first. You cannot merge into an archived repository, and
GitHub reports it as BLOCKED with no protection and no rules, which looks
like a required check:
gh repo view REPO --json isArchived,archivedAtReport an archived repository as skipped, not as a CI failure.
A major bump is a question, not a verdict: does the breaking change reach this project? Ask the deep-check subagent to state the documented breaking change in one sentence, then test it against the repository.
The evidence is the pull request's own CI. A green build on the pull request
proves the new version works there, because the workflow ran with the bump
applied. actions/checkout v7 only blocks fork checkout under
pull_request_target and workflow_run, so this settles it:
for f in $(gh api repos/REPO/contents/.github/workflows --jq '.[].name'); do
gh api "repos/REPO/contents/.github/workflows/$f" --jq .content | base64 -d \
| grep -qE '^\s*(pull_request_target|workflow_run)\s*:' && echo "$f"
doneMerge when the breaking change cannot reach the project and CI is green. Block when it can, and name the mechanism.
Compare against the base branch before you blame the bump:
gh run list -R REPO --limit 6 \
--json conclusion,workflowName,headBranch,createdAtThen read the log and name the error:
gh api --allow-escape-sequences repos/REPO/actions/jobs/JOB_ID/logs \
| perl -pe 's/^.*?\dZ //' | perl -pe 's/(\e|\^\[)\[[0-9;]*m//g' \
| grep -iE 'error|failed' | head -20Two examples from one run. A snapshot job failed with an OpenCV aruco C++
compile error that also failed on master — unrelated, so the bump merged. A
test job failed with npm ERESOLVE, because
@typescript-eslint/eslint-plugin@8.65.0 needs typescript <7 through
ts-api-utils — caused by the bump, so it stayed blocked.
HTTP 410 means the log expired. That is unknown, so it is blocked.
Query the advisory database for both versions, not only the new one:
gh api '/advisories?ecosystem=ECOSYSTEM&affects=NAME@VERSION&per_page=5' \
--jq '.[] | {ghsa_id, severity, summary}'An open advisory that affects the new version blocks the merge. An advisory that the bump repairs is a reason to merge — name the GHSA in the report, because it tells the maintainer which merges are urgent.
An upgrade is not automatically a fix. Check that the new version is
outside the vulnerable range, not merely newer. golang.org/x/image 0.20.0 to
0.38.0 looked like a big catch-up, but GHSA-q675-qj96-32m9 is patched only in
0.41.0, so the bump landed still vulnerable. Block, and say which version
would actually close it.
Before blaming any bump, ask whether the same check fails in unrelated
repositories. If it does, it is a broken tool, and it is one problem rather
than many. A ruleguard / scan job failed on seven pull requests across four
repositories with internal error: package "context" without types, because
the workflow installs it with go install ...@latest against a newer Go. It
even failed on a pull request that only edited YAML, which the linter never
reads — proof on its own that no bump caused it.
Two signals that a red check is not the bump's fault:
Ask the user whether a recurring failure is known-broken, and once they say it is, stop re-deriving it in later runs.
A version number proves nothing about the content. Read the upstream diff for
every bump that is not a patch of a dependency that you already trust, and for
every npm or pypi bump.
Send this work to parallel subagents, one subagent for each dependency. Give each subagent the dependency name, both versions, and the compare URL:
https://github.com/OWNER/REPO/compare/vOLD...vNEWBatch several dependencies into one subagent when they share an ecosystem. Ten subagents for ten dependencies wastes time; three grouped subagents do not.
Ask the subagent to report only evidence, with file and line references:
For a major bump, also ask for the documented breaking change in one sentence. You need it for the impact test above.
Tell the subagent that a minified dist/ bundle is normal in a GitHub Action.
Only a bundle change that does not match the source change in the same diff is
evidence. That rule found a real one: svenstaro/upload-release-action 2.11.5
changed dist/index.js by +37822/-33780 with no source change, and also
shipped the maintainer's .claude/settings.local.json in the release tag.
The subagent reports clean, suspicious, or unknown. Treat suspicious
and unknown as blocked. A compare page that does not exist is blocked,
because the tag does not match the release.
One suspicious entry blocks the whole grouped pull request, even when the
other entries are clean.
When a pull request is blocked for anything a reader would call suspicious, post the evidence as a comment on that pull request, then leave it open. The finding belongs where the next person will look, not only in the report.
Comment for a supply-chain finding: a maintainer set that shrank, a repository that moved, a bundle that does not match its source, an unexplained file in a release tag, an advisory the bump fails to close, or a version published inside the cool-down. A plain red test or a merge conflict does not need a comment.
Write the comment so it stands on its own:
Markdown bodies with backticks break shell heredocs. Write the body to a file first, then:
gh pr comment NUMBER -R REPO --body-file comment.mdMerge only a pull request that passed every check above. A red check is acceptable only when it is not required and you showed that the bump did not cause it.
Use the method that the repository permits:
gh repo view REPO --json squashMergeAllowed,mergeCommitAllowed
gh pr merge NUMBER -R REPO --squash --delete-branchPrefer squash. Use --merge when squash is not permitted. Never rebase.
--delete-branch fails with Cannot use -d or --delete-branch when merge queue enabled. Drop the flag for those repositories.
--auto is only useful when the repository has allow_auto_merge. Otherwise
it merges at once:
gh api repos/REPO --jq .allow_auto_mergegh pr merge prints nothing when it succeeds, and it can fail silently in a
loop. Always verify:
gh pr view NUMBER -R REPO --json state,mergedAtBase branch was modified means the bot replaced the pull request while you
worked. Dependabot closes the old one with "Looks like these dependencies are
updatable in another way"; Renovate silently force-pushes the same branch
instead. Find the replacement, record the old row as skipped, and check the
new pull request from the start:
gh pr list -R REPO --author app/dependabot --state open --json number,titleUpdate the ledger after every merge. A failed merge is state='failed' with
the error text as the reason.
Watch what your own merges did. A merged bump can break the default branch even when the pull request was green, because a workflow may not run on pull requests at all. After a batch, check the default branch, and establish whether a red run predates the merge before claiming either way:
gh run list -R REPO --branch "$(gh api repos/REPO --jq .default_branch)" \
--limit 6 --json conclusion,workflowName,createdAtA run with 0 jobs and "workflow file issue" is a broken workflow file or an
unreachable reusable workflow, not a dependency problem.
One line for each pull request, grouped by result:
Group the blocked ones by cause, so that one broken workflow does not look like
ten bad dependencies. Four pull requests that all fail ruleguard / scan are
one problem.
Close with the count for each group, and the pull requests that need a human. Name the suspicious dependency first, and call out any blocked pull request that is holding back a security fix, because those must not sit forever.
Expect to be asked "what is left?" — every blocked row needs a reason a person can act on, not just a status.
gh repo view --json defaultBranch is not a field. Use defaultBranchRef,
or gh api repos/REPO --jq .default_branch.403 from the rules API does not prove there are no required checks.
See "Which checks matter" before making a merge decision.HTTP 410 on a job log means it expired. That is unknown, so blocked.© caarlos0, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/dependabot-merge of caarlos0/dotfiles.
Open the folder on GitHubat commit 892360f
Dependabot Merge next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependabot Merge this skillcaarlos0/dotfiles | 220 | — | ~5k | Automated safety check: Pass | MIT | |
| Renovate Actions PR Reviewbacknotprop/plannotator | 9.3k | — | ~640 | Automated safety check: Pass | Apache-2.0 | |
| Bump CLI Compatibility Manifestdatabricks/cli | 404 | — | ~1.3k | Automated safety check: Notes | Custom licence | |
| Add Egress Allowlist Domaindependabot/proxy | 137 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Dependabot PR Reviewkernitus/BukkitOldCombatMechanics | 225 | — | ~882 | Automated safety check: Pass | MPL-2.0 | |
| Apply Renovate PRssivaprasadreddy/sivalabs-agent-skills | 188 | — | ~3k | Automated safety check: Pass | MIT |
backnotprop/plannotator
Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.
databricks/cli
Updates the Databricks CLI's cli-compat.json with new AppKit and Agent Skills versions and opens a pull request for the change.
dependabot/proxy
Triage a host that was blocked by the Dependabot proxy egress allowlist, add it to internal/handlers/egressallowlistdefaults.yaml with the correct matching form and regression tests, and open a pull…
kernitus/BukkitOldCombatMechanics
A skill your agent uses for Dependabot PRs, dependency bumps, Gradle or Maven dependency updates, GitHub Actions updates, dependency changelog/licence/release-note review, JVM/classfile checks, and…
sivaprasadreddy/sivalabs-agent-skills
Apply the changes from all open Renovate bot pull requests of a GitHub repository into the local working tree.
itgalaxy/webfont
Process the oldest open pull request end-to-end: analyze the diff, add missing tests on that PR branch, resolve review comments (including Copilot) in a loop, fix test regressions, update…
caarlos0/dotfiles
Design and review command-line interfaces for usability, automation, safety, accessibility, and long-term compatibility.
caarlos0/dotfiles
Use GitHub CLI efficiently for pull requests, CI checks, workflow runs, logs, and merge status.
caarlos0/dotfiles
Design terminal user interfaces and interactive CLIs that stay usable, accessible, and scriptable.
caarlos0/dotfiles
Design and review dashboards that are informative, honest, accessible, and visually polished, independent of any tool.
caarlos0/dotfiles
Author and revise clear GitHub internal documentation, including design docs, proposals, decision records, runbooks, status updates, and handoffs.
caarlos0/dotfiles
Profile and optimize Go CPU, allocations, GC, concurrency, and I/O with benchmarks and pprof.
Categories
Review and merge open dependency pull requests from Dependabot, Renovate and similar bots across the goreleaser organization and the caarlos0 user. Dependabot Merge is an agent skill from caarlos0/dotfiles. Review and merge open dependency pull requests from Dependabot, Renovate and similar bots across the goreleaser organization and the caarlos0 user.
Dependabot Merge fits situations like: dependency update triage; supply-chain checks on bumps; bulk dependency merges.
Run `npx skills add caarlos0/dotfiles --skill dependabot-merge -a claude-code`. Or copy the skill folder (skills/dependabot-merge in caarlos0/dotfiles) into .claude/skills/dependabot-merge in your project. Claude Code loads it when a task matches its description.
Run `npx skills add caarlos0/dotfiles --skill dependabot-merge -a codex`. Or copy the skill folder (skills/dependabot-merge in caarlos0/dotfiles) into .agents/skills/dependabot-merge in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add caarlos0/dotfiles --skill dependabot-merge -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-merge, .gemini/skills/dependabot-merge, .github/skills/dependabot-merge and .opencode/skills/dependabot-merge in your project.
Going by SKILL.md and its folder, Dependabot Merge needs the command-line tools its instructions call (gh, curl, jq, sh, npm and go).
SKILL.md names 2 domains. In commands or code: registry.npmjs.org and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependabot Merge is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependabot Merge: Renovate Actions PR Review (backnotprop/plannotator, 9.3k stars), Bump CLI Compatibility Manifest (databricks/cli, 404 stars), Add Egress Allowlist Domain (dependabot/proxy, 137 stars) and Dependabot PR Review (kernitus/BukkitOldCombatMechanics, 225 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
caarlos0 (a GitHub user) maintains it in caarlos0/dotfiles, which has 220 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 9, 2026.
Source: caarlos0/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.