Finishing a Development Branch
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
Backports a merged pull request from main onto a patch-release branch, e.g.
$ npx skills add DependencyTrack/frontend --skill backport -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install DependencyTrack/frontend backport --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/DependencyTrack/frontend.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/backport .claude/skills/backport && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "backport" agent skill from https://github.com/DependencyTrack/frontend/tree/main/.claude/skills/backport into .claude/skills/backport/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "backport", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/DependencyTrack/frontend/tree/main/.claude/skills/backportType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add DependencyTrack/frontend --skill backport -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install DependencyTrack/frontend backport --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/DependencyTrack/frontend.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/backport .agents/skills/backport && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "backport" agent skill from https://github.com/DependencyTrack/frontend/tree/main/.claude/skills/backport into .agents/skills/backport/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "backport", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add DependencyTrack/frontend --skill backport -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install DependencyTrack/frontend backport --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/DependencyTrack/frontend.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/backport .cursor/skills/backport && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "backport" agent skill from https://github.com/DependencyTrack/frontend/tree/main/.claude/skills/backport into .cursor/skills/backport/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "backport", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/DependencyTrack/frontend.git --path .claude/skills/backport--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add DependencyTrack/frontend --skill backport -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install DependencyTrack/frontend backport --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/DependencyTrack/frontend.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/backport .gemini/skills/backport && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "backport" agent skill from https://github.com/DependencyTrack/frontend/tree/main/.claude/skills/backport into .gemini/skills/backport/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "backport", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install DependencyTrack/frontend backportInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add DependencyTrack/frontend --skill backport -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/DependencyTrack/frontend.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/backport .github/skills/backport && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "backport" agent skill from https://github.com/DependencyTrack/frontend/tree/main/.claude/skills/backport into .github/skills/backport/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "backport", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add DependencyTrack/frontend --skill backport -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install DependencyTrack/frontend backport --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/DependencyTrack/frontend.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/backport .opencode/skills/backport && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "backport" agent skill from https://github.com/DependencyTrack/frontend/tree/main/.claude/skills/backport into .opencode/skills/backport/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "backport", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
backportBackports a merged pull request from main onto a patch-release branch, e.g.
Backport is an agent skill from DependencyTrack/frontend. Backports a merged pull request from main onto a patch-release branch, e.g. 5.0.x. Activates on /backport <PR-number [target-branch], and whenever the user asks to backport, port, or cherry-pick a merged PR, commit, or fix onto a patch, release, or maintenance branch, including phrasings like "backport 1234 to 5.0.x", "cherry-pick that fix onto 5.0.x", or "get this into the next patch release". Not for forward-porting onto main!
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Pull requests and Git worktrees. It works with Vue.js and Git. The repository describes itself as: Frontend UI for Dependency-Track. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1c7be6c. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashAskUserQuestionReadEditFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmghFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cli.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Backport loads about 1.9k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 806 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, AskUserQuestion, Read, EditAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from DependencyTrack/frontend at commit 1c7be6c, republished under its Apache-2.0 licence (© DependencyTrack). 806 words, ~1,876 tokens.
.claude/skills/backport/SKILL.md (or your agent's skills folder).Automates the patch-release backport flow from RELEASING.md §Patch Releases. Invoke as:
/backport <PR-number> [target-branch]Requires an authenticated gh CLI (gh auth status).
git push. Print the push command at the end and let the user run it.Co-Authored-By: Claude ... to any commit.git cherry-pick -x -s (records origin SHA, adds signoff, matches existing patch-branch history)..claude/worktrees/backport-pr-<N>, never in the primary checkout.npm run prettier-fix before committing.AskUserQuestion. DO NOT IMPROVISE.origin may point at a fork. Resolve the canonical remote once and use $CANON everywhere below:
CANON=$(git remote -v | awk '/DependencyTrack\/frontend.*\(fetch\)/ {print $1; exit}')If empty, ask the user which remote tracks the canonical repo.
Confirm CWD is the primary repo (not already a worktree).
Resolve $CANON per §Resolving the canonical remote, then git fetch $CANON.
If target-branch was omitted, derive it from the PR's backport label:
gh pr view <N> --json labels -q '.labels[].name | select(startswith("backport/"))'If backport/5.0.5, the target branch is 5.0.x. On zero or multiple matches,
ask the user via AskUserQuestion, offering branches matching [0-9]+\.[0-9]+\.x.
gh pr view <N> --json state,baseRefName,mergeCommitstate is not MERGED: abort. DO NOT GUESS.baseRefName is not main: tell the user which branch the PR targeted and ask before continuing.
(master still exists on the remote but is stale. Treat it like any other unexpected base.)Take MERGE from mergeCommit.oid, then check how it was merged:
git rev-parse --verify --quiet "${MERGE}^2"^2 resolves): the PR's commits are preserved in main.git log --reverse --format=%H "${MERGE}^1..${MERGE}^2" # oldest first^2 missing): MERGE itself is the only commit to pick.Path: .claude/worktrees/backport-pr-<N> (in-tree, git-ignored).
cd in, verify git status is clean (else ask the user), then git checkout -B backport-pr-<N> $CANON/<target-branch>.git worktree add -b backport-pr-<N> .claude/worktrees/backport-pr-<N> $CANON/<target-branch>.git worktree add errors with a branch named '…' already exists): glance at git log backport-pr-<N> ^$CANON/<target-branch> to confirm nothing valuable, git branch -D backport-pr-<N>, retry.git worktree add half-succeeded (partial directory plus a stale branch), delete both and git worktree prune before retrying.A fresh worktree has no node_modules. Only install (§6) if a check actually needs it.
For each SHA from step 2, in order.
First, skip what is already there:
git log $CANON/<target-branch> --grep="cherry picked from commit <sha>" --format=%HNon-empty means already backported. Skip it and note that in the summary.
Otherwise git cherry-pick -x -s <sha>.
git add, GIT_EDITOR=true git cherry-pick --continue (--continue opens $EDITOR and hangs otherwise).git cherry-pick --abort, recreate manually, commit per §Manual commit format.git cherry-pick --abort, then AskUserQuestion with options (skip / reduced port / port differently). DO NOT INVENT A RESOLUTION.Conflict markers can include unrelated main-only lines that anchored the hunk's context. Naively accepting "incoming" smuggles those into the backport.
Before resolving, run git show <sha> -- <conflicted-file> to show the authoritative diff. If the >>>>>>> side has extra lines git show doesn't list, drop them.
src/i18n/locales/*.json conflict constantly.
Keys are sorted alphabetically and every locale carries every key.
Resolve per key, not per hunk:
en.json with its English value and into every other locale file with a null value.npm run prettier-fix afterwards to restore key order and formatting.For manually-recreated commits (not cherry-picked):
Co-Authored-By: <Name> <email> for the original commit's author. Omit if that email equals git config user.email. Never add Co-Authored-By: Claude ....git commit -s (adds Signed-off-by). Author identity = default git config. Pass the message via HEREDOC.Run from the worktree. Anything beyond the first row needs dependencies first:
npm ci (uses the target branch's package-lock.json, never copy or symlink node_modules
from the primary checkout, the lockfiles differ across branches).
| If any commit touches | Run |
|---|---|
nothing but .github/**, docker/**, docs | nothing |
src/i18n/locales/** | npm run vue-i18n-extract |
src/**, package.json, *.config.js | npm run prettier then npm run build |
npm run eslint is covered by lint.yaml in CI and is slow
locally. Run it only if a resolution changed non-trivial logic.
On failure, report and stop.
Print, in this order:
The worktree path.
One row per commit from step 2. Every commit gets a row, including skipped ones:
| Status | Commit | Subject |
|---|---|---|
picked / manual / skipped / already | <short-sha> | ... |
<short-sha> is the source commit on main, not the new one. For skipped, give the reason.
The push command (DO NOT RUN IT):
cd .claude/worktrees/backport-pr-<N> && git push -u origin backport-pr-<N>If any row is not picked, state that on one line above the table.
© DependencyTrack, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/backport of DependencyTrack/frontend.
Open the folder on GitHubat commit 1c7be6c
Backport next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Backport this skillDependencyTrack/frontend | 172 | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | |
| Finishing a Development Branchobra/superpowers | 297k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Pre-Release PR Triagejamiepine/voicebox | 57k | — | ~3.1k | Automated safety check: Pass | MIT | |
| Cap Feature Building WorkflowCapSoftware/Cap | 23k | — | ~2.5k | Automated safety check: Warn | Custom licence | |
| Lint Commit PRTresjs/tres | 3.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Clean Complete Branchesjtenniswood/espcontrol | 1.1k | — | ~820 | Automated safety check: Pass | Custom licence |
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
jamiepine/voicebox
Sorts a backlog of open pull requests into must-merge, candidate, superseded and deferred, writes a triage doc and works the merge loop before a release.
CapSoftware/Cap
Builds a Cap feature in an isolated Git worktree with disposable dev resources, verification, a recorded demo and a neutral pull request, started with /building.
Tresjs/tres
Lint local changes, auto-fix, conventional commit, and optionally create PR
jtenniswood/espcontrol
Clean up completed Git branches and worktrees for this repository both locally and on GitHub.
MarkBind/markbind
Complete guide for migrating JavaScript files to TypeScript in the MarkBind project, including the two-commit strategy, import/export syntax conversion, and best practices.
Categories
Backports a merged pull request from main onto a patch-release branch, e.g. Backport is an agent skill from DependencyTrack/frontend.g.
Backport fits situations like: tasks that involve Pull requests; tasks that involve Git worktrees.
Run `npx skills add DependencyTrack/frontend --skill backport -a claude-code`. Or copy the skill folder (.claude/skills/backport in DependencyTrack/frontend) into .claude/skills/backport in your project. Claude Code loads it when a task matches its description.
Run `npx skills add DependencyTrack/frontend --skill backport -a codex`. Or copy the skill folder (.claude/skills/backport in DependencyTrack/frontend) into .agents/skills/backport in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DependencyTrack/frontend --skill backport -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/backport, .gemini/skills/backport, .github/skills/backport and .opencode/skills/backport in your project.
Going by SKILL.md and its folder, Backport needs the command-line tools its instructions call (git, npm and gh). Our summary lists: Docker. Its frontmatter pre-approves these tools: Bash, AskUserQuestion, Read, Edit.
SKILL.md names 1 domain. As links in the text: cli.github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Backport is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Backport: Finishing a Development Branch (obra/superpowers, 297k stars), Pre-Release PR Triage (jamiepine/voicebox, 57k stars), Cap Feature Building Workflow (CapSoftware/Cap, 23k stars) and Lint Commit PR (Tresjs/tres, 3.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
DependencyTrack (a GitHub organization) maintains it in DependencyTrack/frontend, which has 172 GitHub stars. The repository was last updated on October 9, 2026.
Source: DependencyTrack/frontend on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.