Agent skill

Backport

by DependencyTrack in DependencyTrack/frontend

Backports a merged pull request from main onto a patch-release branch, e.g.

Apache-2.0Auto-check: notesDevelopment

Install Backport

skills CLI
$ npx skills add DependencyTrack/frontend --skill backport -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DependencyTrack/frontend backport --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DependencyTrack/frontend.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/backport .claude/skills/backport && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
backport
GitHub stars
172
Token cost
~1.9k tokens
SKILL.md length
806 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Backports a merged pull request from main onto a patch-release branch, e.g.

  • Works in 7 steps: Validate state → Locate the PR's commits → Set up the worktree → …
  • Tasks that involve Pull requests
  • SKILL.md covers Rules (DO NOT VIOLATE), Resolving the canonical remote and Workflow
  • Calls git, npm and gh

What it does

Backport is an agent skill from DependencyTrack/frontend. Backports a merged pull request from main onto a patch-release branch, e.g. 5.0.x. Activates on /backport <PR-number [target-branch], and whenever the user asks to backport, port, or cherry-pick a merged PR, commit, or fix onto a patch, release, or maintenance branch, including phrasings like "backport 1234 to 5.0.x", "cherry-pick that fix onto 5.0.x", or "get this into the next patch release". Not for forward-porting onto main!

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests and Git worktrees. It works with Vue.js and Git. The repository describes itself as: Frontend UI for Dependency-Track. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Pull requests
  • Tasks that involve Git worktrees

Example prompts

  • “backport 1234 to 5.0.x”
  • “cherry-pick that fix onto 5.0.x”
  • “get this into the next patch release”
  • “/backport”

Requirements

  • Docker
  • Pre-approved tools (allowed-tools): Bash, AskUserQuestion, Read, Edit

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Validate state
  2. Locate the PR's commits
  3. Set up the worktree
  4. Apply each commit
  5. Manual commit format
  6. Post-backport checks
  7. Summary

What it can do on your machine

Read from SKILL.md and the folder at commit 1c7be6c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • AskUserQuestion
    • Read
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cli.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Backport loads about 1.9k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 806 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, AskUserQuestion, Read, Edit

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DependencyTrack/frontend at commit 1c7be6c, republished under its Apache-2.0 licence (© DependencyTrack). 806 words, ~1,876 tokens.

Download SKILL.mdSave it as .claude/skills/backport/SKILL.md (or your agent's skills folder).
name
backport
description
Backports a merged pull request from `main` onto a patch-release branch, e.g. `5.0.x`. Activates on `/backport <PR-number> [target-branch]`, and whenever the user asks to backport, port, or cherry-pick a merged PR, commit, or fix onto a patch, release, or maintenance branch, including phrasings like "backport #1234 to 5.0.x", "cherry-pick that fix onto 5.0.x", or "get this into the next patch release". Not for forward-porting onto `main`!
allowed-tools
Bash, AskUserQuestion, Read, Edit

Backporting a Pull Request

Automates the patch-release backport flow from RELEASING.md §Patch Releases. Invoke as:

/backport <PR-number> [target-branch]

Requires an authenticated gh CLI (gh auth status).

Rules (DO NOT VIOLATE)

  • Never git push. Print the push command at the end and let the user run it.
  • Never add Co-Authored-By: Claude ... to any commit.
  • Always cherry-pick with git cherry-pick -x -s (records origin SHA, adds signoff, matches existing patch-branch history).
  • Always work in .claude/worktrees/backport-pr-<N>, never in the primary checkout.
  • Never hand-format code. If a resolution touches source, run npm run prettier-fix before committing.
  • If a conflict cannot be resolved unambiguously and does not apply conceptually, ask the user via AskUserQuestion. DO NOT IMPROVISE.

Resolving the canonical remote

origin may point at a fork. Resolve the canonical remote once and use $CANON everywhere below:

sh
CANON=$(git remote -v | awk '/DependencyTrack\/frontend.*\(fetch\)/ {print $1; exit}')

If empty, ask the user which remote tracks the canonical repo.

Workflow

1. Validate state
  • Confirm CWD is the primary repo (not already a worktree).

  • Resolve $CANON per §Resolving the canonical remote, then git fetch $CANON.

  • If target-branch was omitted, derive it from the PR's backport label:

    sh
    gh pr view <N> --json labels -q '.labels[].name | select(startswith("backport/"))'

    If backport/5.0.5, the target branch is 5.0.x. On zero or multiple matches, ask the user via AskUserQuestion, offering branches matching [0-9]+\.[0-9]+\.x.

2. Locate the PR's commits
sh
gh pr view <N> --json state,baseRefName,mergeCommit
  • state is not MERGED: abort. DO NOT GUESS.
  • baseRefName is not main: tell the user which branch the PR targeted and ask before continuing. (master still exists on the remote but is stale. Treat it like any other unexpected base.)

Take MERGE from mergeCommit.oid, then check how it was merged:

sh
git rev-parse --verify --quiet "${MERGE}^2"
  • Merge commit (^2 resolves): the PR's commits are preserved in main.
    sh
    git log --reverse --format=%H "${MERGE}^1..${MERGE}^2"  # oldest first
  • Squash or rebase merge (^2 missing): MERGE itself is the only commit to pick.
3. Set up the worktree

Path: .claude/worktrees/backport-pr-<N> (in-tree, git-ignored).

  • Reuse (path exists, worktree registered): cd in, verify git status is clean (else ask the user), then git checkout -B backport-pr-<N> $CANON/<target-branch>.
  • Fresh: git worktree add -b backport-pr-<N> .claude/worktrees/backport-pr-<N> $CANON/<target-branch>.
  • Leftover branch (worktree gone, branch remains, git worktree add errors with a branch named '…' already exists): glance at git log backport-pr-<N> ^$CANON/<target-branch> to confirm nothing valuable, git branch -D backport-pr-<N>, retry.
  • If git worktree add half-succeeded (partial directory plus a stale branch), delete both and git worktree prune before retrying.

A fresh worktree has no node_modules. Only install (§6) if a check actually needs it.

4. Apply each commit

For each SHA from step 2, in order.

First, skip what is already there:

sh
git log $CANON/<target-branch> --grep="cherry picked from commit <sha>" --format=%H

Non-empty means already backported. Skip it and note that in the summary.

Otherwise git cherry-pick -x -s <sha>.

  • Clean: continue.
  • Trivial conflict (import order, non-overlapping adjacent edits): resolve, git add, GIT_EDITOR=true git cherry-pick --continue (--continue opens $EDITOR and hangs otherwise).
  • Non-trivial but conceptually applies: git cherry-pick --abort, recreate manually, commit per §Manual commit format.
  • Does not apply conceptually (target refactored/removed): git cherry-pick --abort, then AskUserQuestion with options (skip / reduced port / port differently). DO NOT INVENT A RESOLUTION.
Show full SKILL.md (338 more words)Show less
Inspecting a conflict before resolving

Conflict markers can include unrelated main-only lines that anchored the hunk's context. Naively accepting "incoming" smuggles those into the backport.

Before resolving, run git show <sha> -- <conflicted-file> to show the authoritative diff. If the >>>>>>> side has extra lines git show doesn't list, drop them.

Locale files

src/i18n/locales/*.json conflict constantly. Keys are sorted alphabetically and every locale carries every key. Resolve per key, not per hunk:

  • Take only the keys the picked commit actually adds or changes, leave the rest at the target branch's state.
  • A new key goes into en.json with its English value and into every other locale file with a null value.
  • Run npm run prettier-fix afterwards to restore key order and formatting.
5. Manual commit format

For manually-recreated commits (not cherry-picked):

  • Mirror the original subject + body.
  • Add Co-Authored-By: <Name> <email> for the original commit's author. Omit if that email equals git config user.email. Never add Co-Authored-By: Claude ....
  • git commit -s (adds Signed-off-by). Author identity = default git config. Pass the message via HEREDOC.
6. Post-backport checks

Run from the worktree. Anything beyond the first row needs dependencies first: npm ci (uses the target branch's package-lock.json, never copy or symlink node_modules from the primary checkout, the lockfiles differ across branches).

If any commit touchesRun
nothing but .github/**, docker/**, docsnothing
src/i18n/locales/**npm run vue-i18n-extract
src/**, package.json, *.config.jsnpm run prettier then npm run build

npm run eslint is covered by lint.yaml in CI and is slow locally. Run it only if a resolution changed non-trivial logic.

On failure, report and stop.

7. Summary

Print, in this order:

  1. The worktree path.

  2. One row per commit from step 2. Every commit gets a row, including skipped ones:

    StatusCommitSubject
    picked / manual / skipped / already<short-sha>...

    <short-sha> is the source commit on main, not the new one. For skipped, give the reason.

  3. The push command (DO NOT RUN IT):

    sh
    cd .claude/worktrees/backport-pr-<N> && git push -u origin backport-pr-<N>

If any row is not picked, state that on one line above the table.

© DependencyTrack, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/backport of DependencyTrack/frontend.

Open the folder on GitHubat commit 1c7be6c

Compare with similar skills

Backport next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Backport compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Backport this skillDependencyTrack/frontend172—~1.9kAutomated safety check: NotesApache-2.0
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Pre-Release PR Triagejamiepine/voicebox57k—~3.1kAutomated safety check: PassMIT
Cap Feature Building WorkflowCapSoftware/Cap23k—~2.5kAutomated safety check: WarnCustom licence
Lint Commit PRTresjs/tres3.8k—~1.1kAutomated safety check: PassMIT
Clean Complete Branchesjtenniswood/espcontrol1.1k—~820Automated safety check: PassCustom licence

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Pre-Release PR Triage

    jamiepine/voicebox

    Sorts a backlog of open pull requests into must-merge, candidate, superseded and deferred, writes a triage doc and works the merge loop before a release.

    57k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Builds a Cap feature in an isolated Git worktree with disposable dev resources, verification, a recorded demo and a neutral pull request, started with /building.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Lint Commit PR

    Tresjs/tres

    Lint local changes, auto-fix, conventional commit, and optionally create PR

    3.8k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Clean Complete Branches

    jtenniswood/espcontrol

    Clean up completed Git branches and worktrees for this repository both locally and on GitHub.

    1.1k GitHub stars~820 tokensUpdated today
    DevelopmentAuto-check passed
  • Complete guide for migrating JavaScript files to TypeScript in the MarkBind project, including the two-commit strategy, import/export syntax conversion, and best practices.

    158 GitHub stars~2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

Works with

Categories

Questions about Backport

What does Backport do?

Backports a merged pull request from main onto a patch-release branch, e.g. Backport is an agent skill from DependencyTrack/frontend.g.

When should I use Backport?

Backport fits situations like: tasks that involve Pull requests; tasks that involve Git worktrees.

How do I install Backport in Claude Code?

Run `npx skills add DependencyTrack/frontend --skill backport -a claude-code`. Or copy the skill folder (.claude/skills/backport in DependencyTrack/frontend) into .claude/skills/backport in your project. Claude Code loads it when a task matches its description.

How do I install Backport in Codex?

Run `npx skills add DependencyTrack/frontend --skill backport -a codex`. Or copy the skill folder (.claude/skills/backport in DependencyTrack/frontend) into .agents/skills/backport in your project. Codex loads it when a task matches its description.

Can I use Backport in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DependencyTrack/frontend --skill backport -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/backport, .gemini/skills/backport, .github/skills/backport and .opencode/skills/backport in your project.

What does Backport need to run?

Going by SKILL.md and its folder, Backport needs the command-line tools its instructions call (git, npm and gh). Our summary lists: Docker. Its frontmatter pre-approves these tools: Bash, AskUserQuestion, Read, Edit.

Does Backport access the network?

SKILL.md names 1 domain. As links in the text: cli.github.com. This is read from the text; nothing was executed.

Is Backport safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Backport use?

Backport is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Backport use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Backport?

Skills that share tags, products or a category with Backport: Finishing a Development Branch (obra/superpowers, 297k stars), Pre-Release PR Triage (jamiepine/voicebox, 57k stars), Cap Feature Building Workflow (CapSoftware/Cap, 23k stars) and Lint Commit PR (Tresjs/tres, 3.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Backport?

DependencyTrack (a GitHub organization) maintains it in DependencyTrack/frontend, which has 172 GitHub stars. The repository was last updated on October 9, 2026.

Source: DependencyTrack/frontend on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.