Triage Dependabot Alerts
activepieces/activepieces
Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…
Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts.
$ npx skills add decebals/claude-code-java --skill maven-dependency-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install decebals/claude-code-java maven-dependency-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/maven-dependency-audit .claude/skills/maven-dependency-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "maven-dependency-audit" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/maven-dependency-audit into .claude/skills/maven-dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "maven-dependency-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/decebals/claude-code-java/tree/main/skills/maven-dependency-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add decebals/claude-code-java --skill maven-dependency-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install decebals/claude-code-java maven-dependency-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/maven-dependency-audit .agents/skills/maven-dependency-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "maven-dependency-audit" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/maven-dependency-audit into .agents/skills/maven-dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "maven-dependency-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add decebals/claude-code-java --skill maven-dependency-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install decebals/claude-code-java maven-dependency-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/maven-dependency-audit .cursor/skills/maven-dependency-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "maven-dependency-audit" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/maven-dependency-audit into .cursor/skills/maven-dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "maven-dependency-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/decebals/claude-code-java.git --path skills/maven-dependency-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add decebals/claude-code-java --skill maven-dependency-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install decebals/claude-code-java maven-dependency-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/maven-dependency-audit .gemini/skills/maven-dependency-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "maven-dependency-audit" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/maven-dependency-audit into .gemini/skills/maven-dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "maven-dependency-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install decebals/claude-code-java maven-dependency-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add decebals/claude-code-java --skill maven-dependency-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/maven-dependency-audit .github/skills/maven-dependency-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "maven-dependency-audit" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/maven-dependency-audit into .github/skills/maven-dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "maven-dependency-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add decebals/claude-code-java --skill maven-dependency-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install decebals/claude-code-java maven-dependency-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/maven-dependency-audit .opencode/skills/maven-dependency-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "maven-dependency-audit" agent skill from https://github.com/decebals/claude-code-java/tree/main/skills/maven-dependency-audit into .opencode/skills/maven-dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "maven-dependency-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
maven-dependency-auditAudit Maven dependencies for outdated versions, security vulnerabilities, and conflicts.
Maven Dependency Audit is an agent skill from decebals/claude-code-java. Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. Use when user says "check dependencies", "audit dependencies", "outdated deps", or before releases.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).
It sits in Development, covering Dependency management. The repository describes itself as: Reusable AI development infrastructure for Java projects, optimized for Claude Code. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0d98fe9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
mvnFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Maven Dependency Audit loads about 1.7k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 339 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from decebals/claude-code-java at commit 0d98fe9, republished under its MIT licence (© decebals). 339 words, ~1,663 tokens.
.claude/skills/maven-dependency-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Audit Maven dependencies for updates, vulnerabilities, and conflicts.
mvn versions:display-dependency-updates[INFO] The following dependencies in Dependencies have newer versions:
[INFO] org.slf4j:slf4j-api ......................... 1.7.36 -> 2.0.9
[INFO] com.fasterxml.jackson.core:jackson-databind . 2.14.0 -> 2.16.1
[INFO] org.junit.jupiter:junit-jupiter ............. 5.9.0 -> 5.10.1| Category | Criteria | Action |
|---|---|---|
| Security | CVE fix in newer version | Update ASAP |
| Major | x.0.0 change | Review changelog, test thoroughly |
| Minor | x.y.0 change | Usually safe, test |
| Patch | x.y.z change | Safe, minimal testing |
mvn versions:display-plugin-updatesmvn dependency:treemvn dependency:tree -Dincludes=org.slf4jLook for:
[INFO] +- com.example:module-a:jar:1.0:compile
[INFO] | \- org.slf4j:slf4j-api:jar:1.7.36:compile
[INFO] +- com.example:module-b:jar:1.0:compile
[INFO] | \- org.slf4j:slf4j-api:jar:2.0.9:compile (omitted for conflict)Flags:
(omitted for conflict) - Version conflict resolved by Maven(omitted for duplicate) - Same version, no issuemvn dependency:analyzeOutput:
[WARNING] Used undeclared dependencies found:
[WARNING] org.slf4j:slf4j-api:jar:2.0.9:compile
[WARNING] Unused declared dependencies found:
[WARNING] commons-io:commons-io:jar:2.11.0:compileAdd to pom.xml:
<plugin>
<groupId>org.owasp</groupId>
<artifactId>dependency-check-maven</artifactId>
<version>9.0.7</version>
</plugin>Run:
mvn dependency-check:checkOutput: HTML report in target/dependency-check-report.html
mvn dependency:analyze-reportIf using GitHub, enable Dependabot alerts in repository settings.
| CVSS Score | Severity | Action |
|---|---|---|
| 9.0 - 10.0 | Critical | Update immediately |
| 7.0 - 8.9 | High | Update within days |
| 4.0 - 6.9 | Medium | Update within weeks |
| 0.1 - 3.9 | Low | Update at convenience |
## Dependency Audit Report
**Project:** {project-name}
**Date:** {date}
**Total Dependencies:** {count}
### Security Issues
| Dependency | Current | CVE | Severity | Fixed In |
|------------|---------|-----|----------|----------|
| log4j-core | 2.14.0 | CVE-2021-44228 | Critical | 2.17.1 |
### Outdated Dependencies
#### Major Updates (Review Required)
| Dependency | Current | Latest | Notes |
|------------|---------|--------|-------|
| slf4j-api | 1.7.36 | 2.0.9 | API changes, see migration guide |
#### Minor/Patch Updates (Safe)
| Dependency | Current | Latest |
|------------|---------|--------|
| junit-jupiter | 5.9.0 | 5.10.1 |
| jackson-databind | 2.14.0 | 2.16.1 |
### Conflicts Detected
- slf4j-api: 1.7.36 vs 2.0.9 (resolved to 2.0.9)
### Unused Dependencies
- commons-io:commons-io:2.11.0 (consider removing)
### Recommendations
1. **Immediate:** Update log4j-core to fix CVE-2021-44228
2. **This sprint:** Update minor/patch versions
3. **Plan:** Evaluate slf4j 2.x migration# Quick check
mvn versions:display-dependency-updates -q
# Full audit
mvn versions:display-dependency-updates && \
mvn dependency:analyze && \
mvn dependency-check:checkmvn dependency:tree -Dincludes=commons-logging<dependencyManagement>
<dependencies>
<dependency>
<groupId>org.slf4j</groupId>
<artifactId>slf4j-api</artifactId>
<version>2.0.9</version>
</dependency>
</dependencies>
</dependencyManagement><dependency>
<groupId>com.example</groupId>
<artifactId>some-library</artifactId>
<version>1.0</version>
<exclusions>
<exclusion>
<groupId>commons-logging</groupId>
<artifactId>commons-logging</artifactId>
</exclusion>
</exclusions>
</dependency>-q (quiet) flag for less verbose output-Dincludes=groupId:artifactId when looking for specific deps| Task | Command |
|---|---|
| Outdated deps | mvn versions:display-dependency-updates |
| Outdated plugins | mvn versions:display-plugin-updates |
| Dependency tree | mvn dependency:tree |
| Find specific dep | mvn dependency:tree -Dincludes=groupId |
| Unused deps | mvn dependency:analyze |
| Security scan | mvn dependency-check:check |
| Update versions | mvn versions:use-latest-releases |
| Update snapshots | mvn versions:use-latest-snapshots |
# Update all to latest (use with caution!)
mvn versions:use-latest-releases
mvn versions:commit # or versions:revert# Update specific dependency
mvn versions:use-latest-versions -Dincludes=org.junit.jupiter© decebals, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/maven-dependency-audit of decebals/claude-code-java.
Open the folder on GitHubat commit 0d98fe9
Maven Dependency Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Maven Dependency Audit this skilldecebals/claude-code-java | 751 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Triage Dependabot Alertsactivepieces/activepieces | 25k | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Golang Continuous Integrationsamber/cc-skills-golang | 3.4k | — | ~3.7k | Automated safety check: Pass | MIT | |
| Golang Continuous Integrationcontext-labs/whip | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | |
| Gem Dependency Managementruby-git/ruby-git | 1.8k | — | ~806 | Automated safety check: Pass | MIT | |
| Stash Supply Chain Securitycipherstash/stack | 157 | — | ~5.2k | Automated safety check: Warn | MIT |
activepieces/activepieces
Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…
samber/cc-skills-golang
GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…
context-labs/whip
CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.
ruby-git/ruby-git
Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.
cipherstash/stack
Supply-chain security controls for the @cipherstash/stack monorepo.
dralgorhythm/claude-agentic-framework
Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.
decebals/claude-code-java
A practical Java reference for Builder, Factory, Singleton, Strategy, Observer and other patterns, with a table matching problems to patterns.
decebals/claude-code-java
JPA/Hibernate patterns and common pitfalls (N+1, lazy loading, transactions, queries).
decebals/claude-code-java
Java logging best practices with SLF4J, structured logging (JSON), and MDC for request tracing.
decebals/claude-code-java
Reviews REST API design for correct HTTP verbs, versioning, DTO use, consistent responses and backward compatibility before an API change ships.
decebals/claude-code-java
Reviews a Java project's architecture at the macro level: package structure, module boundaries, dependency direction and layering.
decebals/claude-code-java
Builds changelog entries from conventional commits in a Java project, after working out whether it uses SemVer, two-part versions or calendar versions.
Categories
Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. Maven Dependency Audit is an agent skill from decebals/claude-code-java. Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts.
Maven Dependency Audit fits situations like: user says check dependencies; audit dependencies; before releases.
Run `npx skills add decebals/claude-code-java --skill maven-dependency-audit -a claude-code`. Or copy the skill folder (skills/maven-dependency-audit in decebals/claude-code-java) into .claude/skills/maven-dependency-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add decebals/claude-code-java --skill maven-dependency-audit -a codex`. Or copy the skill folder (skills/maven-dependency-audit in decebals/claude-code-java) into .agents/skills/maven-dependency-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add decebals/claude-code-java --skill maven-dependency-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/maven-dependency-audit, .gemini/skills/maven-dependency-audit, .github/skills/maven-dependency-audit and .opencode/skills/maven-dependency-audit in your project.
Going by SKILL.md and its folder, Maven Dependency Audit needs the command-line tools its instructions call (mvn).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Maven Dependency Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Maven Dependency Audit: Triage Dependabot Alerts (activepieces/activepieces, 25k stars), Golang Continuous Integration (samber/cc-skills-golang, 3.4k stars), Golang Continuous Integration (context-labs/whip, 1.1k stars) and Gem Dependency Management (ruby-git/ruby-git, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
decebals (a GitHub user) maintains it in decebals/claude-code-java, which has 751 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 6, 2026.
Source: decebals/claude-code-java on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.