Dep Auditor
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
Smart dependency management for any language. An agent skill from Asvarox/allkaraoke.
$ npx skills add Asvarox/allkaraoke --skill dependency-updater -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Asvarox/allkaraoke dependency-updater --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Asvarox/allkaraoke.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependency-updater .claude/skills/dependency-updater && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-updater" agent skill from https://github.com/Asvarox/allkaraoke/tree/master/.agents/skills/dependency-updater into .claude/skills/dependency-updater/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updater", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Asvarox/allkaraoke/tree/master/.agents/skills/dependency-updaterType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Asvarox/allkaraoke --skill dependency-updater -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Asvarox/allkaraoke dependency-updater --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Asvarox/allkaraoke.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/dependency-updater .agents/skills/dependency-updater && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-updater" agent skill from https://github.com/Asvarox/allkaraoke/tree/master/.agents/skills/dependency-updater into .agents/skills/dependency-updater/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updater", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Asvarox/allkaraoke --skill dependency-updater -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Asvarox/allkaraoke dependency-updater --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Asvarox/allkaraoke.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/dependency-updater .cursor/skills/dependency-updater && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-updater" agent skill from https://github.com/Asvarox/allkaraoke/tree/master/.agents/skills/dependency-updater into .cursor/skills/dependency-updater/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updater", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Asvarox/allkaraoke.git --path .agents/skills/dependency-updater--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Asvarox/allkaraoke --skill dependency-updater -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Asvarox/allkaraoke dependency-updater --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Asvarox/allkaraoke.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/dependency-updater .gemini/skills/dependency-updater && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-updater" agent skill from https://github.com/Asvarox/allkaraoke/tree/master/.agents/skills/dependency-updater into .gemini/skills/dependency-updater/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updater", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Asvarox/allkaraoke dependency-updaterInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Asvarox/allkaraoke --skill dependency-updater -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Asvarox/allkaraoke.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/dependency-updater .github/skills/dependency-updater && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-updater" agent skill from https://github.com/Asvarox/allkaraoke/tree/master/.agents/skills/dependency-updater into .github/skills/dependency-updater/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updater", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Asvarox/allkaraoke --skill dependency-updater -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Asvarox/allkaraoke dependency-updater --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Asvarox/allkaraoke.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/dependency-updater .opencode/skills/dependency-updater && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-updater" agent skill from https://github.com/Asvarox/allkaraoke/tree/master/.agents/skills/dependency-updater into .opencode/skills/dependency-updater/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updater", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-updaterSmart dependency management for any language. An agent skill from Asvarox/allkaraoke.
Dependency Updater is an agent skill from Asvarox/allkaraoke. Smart dependency management for any language. Auto-detects project type, applies safe updates automatically, prompts for major versions, diagnoses and fixes dependency issues.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `README.md`, `scripts/check-tool.sh` and `scripts/run-taze.sh`).
It sits in Development, covering Dependency management. It works with .NET, Ruby and Rust. The repository describes itself as: Online Karaoke game with pitch detection in your browser. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 15460f4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
npmbundlepipcargomvndotnetgopythonjqnpxyarnFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Updater loads about 3.5k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 633 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from Asvarox/allkaraoke at commit 15460f4, republished under its MIT licence (© Asvarox). 633 words, ~3,470 tokens.
.claude/skills/dependency-updater/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Smart dependency management for any language with automatic detection and safe updates.
update my dependenciesThe skill auto-detects your project type and handles the rest.
| Trigger | Example |
|---|---|
| Update dependencies | "update dependencies", "update deps" |
| Check outdated | "check for outdated packages" |
| Fix dependency issues | "fix my dependency problems" |
| Security audit | "audit dependencies for vulnerabilities" |
| Diagnose deps | "diagnose dependency issues" |
| Language | Package File | Update Tool | Audit Tool |
|---|---|---|---|
| Node.js | package.json | taze | npm audit |
| Python | requirements.txt, pyproject.toml | pip-review | safety, pip-audit |
| Go | go.mod | go get -u | govulncheck |
| Rust | Cargo.toml | cargo update | cargo audit |
| Ruby | Gemfile | bundle update | bundle audit |
| Java | pom.xml, build.gradle | mvn versions:* | mvn dependency:* |
| .NET | *.csproj | dotnet outdated | dotnet list package --vulnerable |
| Update Type | Version Change | Action |
|---|---|---|
| Fixed | No ^ or ~ | Skip (intentionally pinned) |
| PATCH | x.y.z → x.y.Z | Auto-apply |
| MINOR | x.y.z → x.Y.0 | Auto-apply |
| MAJOR | x.y.z → X.0.0 | Prompt user individually |
User Request
│
▼
┌─────────────────────────────────────────────────────┐
│ Step 1: DETECT PROJECT TYPE │
│ • Scan for package files (package.json, go.mod...) │
│ • Identify package manager │
├─────────────────────────────────────────────────────┤
│ Step 2: CHECK PREREQUISITES │
│ • Verify required tools are installed │
│ • Suggest installation if missing │
├─────────────────────────────────────────────────────┤
│ Step 3: SCAN FOR UPDATES │
│ • Run language-specific outdated check │
│ • Categorize: MAJOR / MINOR / PATCH / Fixed │
├─────────────────────────────────────────────────────┤
│ Step 4: AUTO-APPLY SAFE UPDATES │
│ • Apply MINOR and PATCH automatically │
│ • Report what was updated │
├─────────────────────────────────────────────────────┤
│ Step 5: PROMPT FOR MAJOR UPDATES │
│ • AskUserQuestion for each MAJOR update │
│ • Show current → new version │
├─────────────────────────────────────────────────────┤
│ Step 6: APPLY APPROVED MAJORS │
│ • Update only approved packages │
├─────────────────────────────────────────────────────┤
│ Step 7: FINALIZE │
│ • Run install command │
│ • Run security audit │
├─────────────────────────────────────────────────────┤
│ Step 8: DOCUMENT │
│ • Update docs/dependency-updates-report.md │
│ • Explain every override/resolution added │
│ • Record unresolved audit or peer follow-up │
└─────────────────────────────────────────────────────┘# Check prerequisites
scripts/check-tool.sh taze "npm install -g taze"
# Scan for updates
taze
# Apply minor/patch
taze minor --write
# Apply specific majors
taze major --write --include pkg1,pkg2
# Monorepo support
taze -r # recursive
# Security
npm audit
npm audit fixFor Node.js projects that add or keep pnpm.overrides, overrides, resolutions, or other transitive pins, you MUST update docs/dependency-updates-report.md as part of the same task.
That report must include:
If the file does not exist yet, create it.
# Check outdated
pip list --outdated
# Update all (careful!)
pip-review --auto
# Update specific
pip install --upgrade package-name
# Security
pip-audit
safety check# Check outdated
go list -m -u all
# Update all
go get -u ./...
# Tidy up
go mod tidy
# Security
govulncheck ./...# Check outdated
cargo outdated
# Update within semver
cargo update
# Security
cargo audit# Check outdated
bundle outdated
# Update all
bundle update
# Update specific
bundle update --conservative gem-name
# Security
bundle audit# Check outdated
mvn versions:display-dependency-updates
# Update to latest
mvn versions:use-latest-releases
# Security
mvn dependency:tree
mvn dependency-check:check# Check outdated
dotnet list package --outdated
# Update specific
dotnet add package PackageName
# Security
dotnet list package --vulnerableWhen dependencies are broken, run diagnosis:
| Issue | Symptoms | Fix |
|---|---|---|
| Version Conflict | "Cannot resolve dependency tree" | Clean install, use overrides/resolutions |
| Peer Dependency | "Peer dependency not satisfied" | Install required peer version |
| Security Vuln | npm audit shows issues | npm audit fix or manual update |
| Unused Deps | Bloated bundle | Run depcheck (Node) or equivalent |
| Duplicate Deps | Multiple versions installed | Run npm dedupe or equivalent |
| Temporary Override Drift | Nobody remembers why an override exists | Update docs/dependency-updates-report.md in the same change |
# Node.js - Nuclear reset
rm -rf node_modules package-lock.json
npm cache clean --force
npm install
# Python - Clean virtualenv
rm -rf venv
python -m venv venv
source venv/bin/activate
pip install -r requirements.txt
# Go - Reset modules
rm go.sum
go mod tidyRun security checks for any project:
# Node.js
npm audit
npm audit --json | jq '.metadata.vulnerabilities'
# Python
pip-audit
safety check
# Go
govulncheck ./...
# Rust
cargo audit
# Ruby
bundle audit
# .NET
dotnet list package --vulnerable| Severity | Action |
|---|---|
| Critical | Fix immediately |
| High | Fix within 24h |
| Moderate | Fix within 1 week |
| Low | Fix in next release |
| Avoid | Why | Instead |
|---|---|---|
| Update fixed versions | Intentionally pinned | Skip them |
| Auto-apply MAJOR | Breaking changes | Prompt user |
| Batch MAJOR prompts | Loses context | Prompt individually |
| Skip lock file | Irreproducible builds | Always commit lock files |
| Ignore security alerts | Vulnerabilities | Address by severity |
After updates:
docs/dependency-updates-report.md updated if overrides or resolutions remain, and it only lists the currently present overrides/resolutions with rationale and dependency chains<details>
<summary><strong>Deep Dive: Project Detection</strong></summary>
The skill auto-detects project type by scanning for package files:
| File Found | Language | Package Manager |
|---|---|---|
package.json | Node.js | npm/yarn/pnpm |
requirements.txt | Python | pip |
pyproject.toml | Python | pip/poetry |
Pipfile | Python | pipenv |
go.mod | Go | go modules |
Cargo.toml | Rust | cargo |
Gemfile | Ruby | bundler |
pom.xml | Java | Maven |
build.gradle | Java/Kotlin | Gradle |
*.csproj | .NET | dotnet |
Detection order matters for monorepos:
</details>
<details>
<summary><strong>Deep Dive: Node.js with taze</strong></summary>
# Install taze globally (recommended)
npm install -g taze
# Or use npx
npx taze# 1. Scan all updates
taze
# 2. Apply safe updates (minor + patch)
taze minor --write
# 3. For each major, prompt user:
# "Update @types/node from ^20.0.0 to ^22.0.0?"
# If yes, add to approved list
# 4. Apply approved majors
taze major --write --include approved-pkg1,approved-pkg2
# 5. Install
npm install # or pnpm install / yarnSome packages have frequent major bumps but are backward-compatible:
| Package | Reason |
|---|---|
lucide-react | Icon library, majors are additive |
@types/* | Type definitions, usually safe |
</details>
<details>
<summary><strong>Deep Dive: Version Strategies</strong></summary>
MAJOR.MINOR.PATCH (e.g., 2.3.1)
MAJOR: Breaking changes - requires code changes
MINOR: New features - backward compatible
PATCH: Bug fixes - backward compatible| Specifier | Meaning | Example |
|---|---|---|
^1.2.3 | Minor + Patch OK | >=1.2.3 <2.0.0 |
~1.2.3 | Patch only | >=1.2.3 <1.3.0 |
1.2.3 | Exact (fixed) | Only 1.2.3 |
>=1.2.3 | At least | Any >=1.2.3 |
* | Any | Latest (dangerous) |
{
"dependencies": {
"critical-lib": "1.2.3", // Exact for critical
"stable-lib": "~1.2.3", // Patch only for stable
"modern-lib": "^1.2.3" // Minor OK for active
}
}</details>
<details>
<summary><strong>Deep Dive: Conflict Resolution</strong></summary>
Diagnosis:
npm ls package-name # See dependency tree
npm explain package-name # Why installed
yarn why package-name # Yarn equivalentResolution with overrides:
// package.json
{
"overrides": {
"lodash": "^4.18.0"
}
}Resolution with resolutions (Yarn):
{
"resolutions": {
"lodash": "^4.18.0"
}
}Diagnosis:
pip check
pipdeptree -p package-nameResolution:
# Use virtual environment
python -m venv venv
source venv/bin/activate
pip install -r requirements.txt
# Or use constraints
pip install -c constraints.txt -r requirements.txt</details>
| Script | Purpose |
|---|---|
scripts/check-tool.sh | Verify tool is installed |
scripts/run-taze.sh | Run taze with proper flags |
| Tool | Language | Purpose |
|---|---|---|
| taze | Node.js | Smart dependency updates |
| npm-check-updates | Node.js | Alternative to taze |
| pip-review | Python | Interactive pip updates |
| cargo-edit | Rust | Cargo dependency management |
| bundler-audit | Ruby | Security auditing |
© Asvarox, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts) in .agents/skills/dependency-updater of Asvarox/allkaraoke.
Open the folder on GitHubat commit 15460f4
We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 4 other GitHub owners. This page covers the copy in Asvarox/allkaraoke, which our catalogue first saw on October 7, 2026.
Dependency Updater next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Updater this skillAsvarox/allkaraoke | 261 | 4 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Dep Auditorlaolaoshiren/claude-code-skills-zh | 879 | — | ~895 | Automated safety check: Pass | MIT | |
| Pyroscopegrafana/skills | 281 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Interlinked Supply ChainQuentinCody/interlinked-cli | 178 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Sca AuditOWASP/secure-agent-playbook | 187 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | |
| Update .NET OS Packagesdotnet/core | 22k | — | ~2.3k | Automated safety check: Pass | MIT |
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
grafana/skills
Continuously profile applications with Grafana Pyroscope and read the result as flame graphs.
QuentinCody/interlinked-cli
Respond to blocked package installs and manage the Interlinked supply-chain allowlist.
OWASP/secure-agent-playbook
Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.
dotnet/core
Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
Asvarox/allkaraoke
A skill your agent uses when executing implementation plans with independent tasks in the current session
Asvarox/allkaraoke
Guide for migrating a project from ESLint to Oxlint. An agent skill from Asvarox/allkaraoke.
Asvarox/allkaraoke
Run, write, and debug Playwright E2E tests for this project.
Asvarox/allkaraoke
The design language for this project and how to style UI with it — the colour, type, surface and layer tokens, when to reach for an AKUI component instead of writing classes, and when TWC…
Asvarox/allkaraoke
Patterns and guidelines for writing Playwright E2E tests in this project — page object rules, assertion placement, and locator conventions.
Asvarox/allkaraoke
A skill your agent uses when Codex updates, fixes, or adds unit tests in this project.
Categories
Smart dependency management for any language. An agent skill from Asvarox/allkaraoke. Dependency Updater is an agent skill from Asvarox/allkaraoke. Smart dependency management for any language.
Dependency Updater fits situations like: tasks that involve Dependency management.
Run `npx skills add Asvarox/allkaraoke --skill dependency-updater -a claude-code`. Or copy the skill folder (.agents/skills/dependency-updater in Asvarox/allkaraoke) into .claude/skills/dependency-updater in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Asvarox/allkaraoke --skill dependency-updater -a codex`. Or copy the skill folder (.agents/skills/dependency-updater in Asvarox/allkaraoke) into .agents/skills/dependency-updater in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Asvarox/allkaraoke --skill dependency-updater -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-updater, .gemini/skills/dependency-updater, .github/skills/dependency-updater and .opencode/skills/dependency-updater in your project.
Going by SKILL.md and its folder, Dependency Updater needs a shell for the scripts in its folder and the command-line tools its instructions call (npm, bundle, pip, cargo, mvn and dotnet). Our summary lists: Python 3; Node.js; A Bash shell.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Dependency Updater is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependency Updater: Dep Auditor (laolaoshiren/claude-code-skills-zh, 879 stars), Pyroscope (grafana/skills, 281 stars), Interlinked Supply Chain (QuentinCody/interlinked-cli, 178 stars) and Sca Audit (OWASP/secure-agent-playbook, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Asvarox (a GitHub user) maintains it in Asvarox/allkaraoke, which has 261 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.
Source: Asvarox/allkaraoke on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.