GitVersion .NET Development
GitTools/GitVersion
Gives repository-specific .NET guidance for GitVersion: build and test commands, central package management, project layout and coding conventions.
Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.
$ npx skills add express-validator/express-validator --skill upgrade-validator -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install express-validator/express-validator upgrade-validator --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/express-validator/express-validator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/upgrade-validator .claude/skills/upgrade-validator && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "upgrade-validator" agent skill from https://github.com/express-validator/express-validator/tree/master/.agents/skills/upgrade-validator into .claude/skills/upgrade-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-validator", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/express-validator/express-validator/tree/master/.agents/skills/upgrade-validatorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add express-validator/express-validator --skill upgrade-validator -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install express-validator/express-validator upgrade-validator --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/express-validator/express-validator.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/upgrade-validator .agents/skills/upgrade-validator && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "upgrade-validator" agent skill from https://github.com/express-validator/express-validator/tree/master/.agents/skills/upgrade-validator into .agents/skills/upgrade-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-validator", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add express-validator/express-validator --skill upgrade-validator -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install express-validator/express-validator upgrade-validator --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/express-validator/express-validator.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/upgrade-validator .cursor/skills/upgrade-validator && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "upgrade-validator" agent skill from https://github.com/express-validator/express-validator/tree/master/.agents/skills/upgrade-validator into .cursor/skills/upgrade-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-validator", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/express-validator/express-validator.git --path .agents/skills/upgrade-validator--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add express-validator/express-validator --skill upgrade-validator -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install express-validator/express-validator upgrade-validator --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/express-validator/express-validator.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/upgrade-validator .gemini/skills/upgrade-validator && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "upgrade-validator" agent skill from https://github.com/express-validator/express-validator/tree/master/.agents/skills/upgrade-validator into .gemini/skills/upgrade-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-validator", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install express-validator/express-validator upgrade-validatorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add express-validator/express-validator --skill upgrade-validator -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/express-validator/express-validator.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/upgrade-validator .github/skills/upgrade-validator && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "upgrade-validator" agent skill from https://github.com/express-validator/express-validator/tree/master/.agents/skills/upgrade-validator into .github/skills/upgrade-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-validator", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add express-validator/express-validator --skill upgrade-validator -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install express-validator/express-validator upgrade-validator --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/express-validator/express-validator.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/upgrade-validator .opencode/skills/upgrade-validator && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "upgrade-validator" agent skill from https://github.com/express-validator/express-validator/tree/master/.agents/skills/upgrade-validator into .opencode/skills/upgrade-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-validator", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
upgrade-validatorWalks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.
express-validator holds the validator dependency to patch-only semver so an unexpected upstream minor release cannot slip in, which makes each bump a deliberate maintainer task. The workflow notes the previous version from package.json, runs npm install validator@latest, and if npm rewrites the range with a caret, changes it back to a tilde range to match the project's convention.
Next it maps upstream changes onto the codebase, using a tag-range compare on the validator.js repository and its changelog rather than commit titles alone. For each new validator it adds a signature to src/chain/validators.ts and an implementation to src/chain/validators-impl.ts, both in alphabetical order and delegating through addStandardValidation like neighboring methods; new sanitizers get a matching entry in src/chain/sanitizers.ts. The description also lists option types and declarations/validator.d.ts among the files kept in step.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 48d44de. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Validator Dependency Upgrade loads about 1.2k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 448 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from express-validator/express-validator at commit 48d44de, republished under its MIT licence (© express-validator). 448 words, ~1,161 tokens.
.claude/skills/upgrade-validator/SKILL.md (or your agent's skills folder).This project does not float on arbitrary new minor lines of validatorjs/validator.js. As described in express-validator#1253, the validator dependency is pinned to patch (e.g. ~x.y.z) so a new minor from upstream cannot be pulled in implicitly and surface mistaken or unexpected breaking changes. Bumping validator is a deliberate maintainers’ task: run this workflow, sync types and chain APIs, test, and ship.
After npm install, keep package.json consistent with that policy (typically ~<resolved-version>, not a loose ^ on the major/minor line unless the project explicitly changes policy).
validator version from package.json (and confirm after upgrade from package.json / lockfile).v<old>...v<new>) to see commits and the diff between versions.From the repo root, install the latest validator in-range and persist it to package.json / the lockfile:
npm install validator@latestIf npm rewrites the range to ^ and the project uses patch-only pinning per #1253, change the dependency to ~<version> to match the previous convention.
For each new validator, sanitizer, or option type introduced between the old and new version (use the GitHub compare / changelog, not only commit titles):
src/chain/validators.ts: under // validator's validators, add the new method signature in alphabetical order with the rest. Follow existing JSDoc style for adjacent methods.src/chain/validators-impl.ts: under // Standard validators, add the implementation in alphabetical order, delegating with addStandardValidation(validator.<name>, ...) the same way sibling methods do. If upstream uses custom logic (see e.g. isAlpha, toArray-style), match the existing pattern in that file.src/chain/sanitizers.ts: under // validator's sanitizers, add the method in alphabetical order.src/chain/sanitizers-impl.ts: under // Standard sanitizers, add the implementation in alphabetical order (addStandardSanitization vs customSanitizer as appropriate).src/options.ts: add or extend types only when the new value is:{ min, max }, or other structured options).options.ts for parameters that are only a plain string or number with no new shared option shape—use inline types on the chain method if needed, consistent with nearby code.declarations/validator.d.ts: new export function entries must stay in alphabetical order and match the installed validator call signatures. Reuse import('../src/options').<Type> for option types the same way existing declarations do.From the repo root:
npm test
npm run lint
npm run docs:regenerate-apiFix any failures before finishing.
| File | Section comment |
|---|---|
src/chain/validators.ts | // validator's validators |
src/chain/validators-impl.ts | // Standard validators |
src/chain/sanitizers.ts | // validator's sanitizers |
src/chain/sanitizers-impl.ts | // Standard sanitizers |
© express-validator, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/upgrade-validator of express-validator/express-validator.
Open the folder on GitHubat commit 48d44de
Validator Dependency Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Validator Dependency Upgrade this skillexpress-validator/express-validator | 6.2k | — | ~1.2k | Automated safety check: Pass | MIT | |
| GitVersion .NET DevelopmentGitTools/GitVersion | 3.1k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Claude Code Version Checkykdojo/claude-code-tips | 10k | — | ~1.8k | Automated safety check: Pass | Custom licence | |
| Setup Pre Commitfossasia/eventyay-interpretation | 1.6k | 12 repos | ~565 | Automated safety check: Pass | Apache-2.0 | |
| Bun Runtimespinspire/pocketbase-sveltekit-starter | 511 | 5 repos | ~653 | Automated safety check: Notes | MIT | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT |
GitTools/GitVersion
Gives repository-specific .NET guidance for GitVersion: build and test commands, central package management, project layout and coding conventions.
ykdojo/claude-code-tips
Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.
fossasia/eventyay-interpretation
Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo.
spinspire/pocketbase-sveltekit-starter
Bun as runtime, package manager, bundler, and test runner. An agent skill from spinspire/pocketbase-sveltekit-starter.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
aubepkg/aube
Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.
Categories
Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release. express-validator holds the validator dependency to patch-only semver so an unexpected upstream minor release cannot slip in, which makes each bump a deliberate maintainer task.json, runs npm install validator@latest, and if npm rewrites the range with a caret, changes it back to a tilde range to match the project's convention.
Validator Dependency Upgrade fits situations like: bumping validator to a newer release inside the express-validator repository; adding chain methods for validators or sanitizers that are new in validator.js; keeping declarations/validator.d.ts aligned with the upstream package.
Run `npx skills add express-validator/express-validator --skill upgrade-validator -a claude-code`. Or copy the skill folder (.agents/skills/upgrade-validator in express-validator/express-validator) into .claude/skills/upgrade-validator in your project. Claude Code loads it when a task matches its description.
Run `npx skills add express-validator/express-validator --skill upgrade-validator -a codex`. Or copy the skill folder (.agents/skills/upgrade-validator in express-validator/express-validator) into .agents/skills/upgrade-validator in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add express-validator/express-validator --skill upgrade-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-validator, .gemini/skills/upgrade-validator, .github/skills/upgrade-validator and .opencode/skills/upgrade-validator in your project.
Going by SKILL.md and its folder, Validator Dependency Upgrade needs the command-line tools its instructions call (npm). Our summary lists: npm; A checkout of the express-validator repository.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Validator Dependency Upgrade is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Validator Dependency Upgrade: GitVersion .NET Development (GitTools/GitVersion, 3.1k stars), Claude Code Version Check (ykdojo/claude-code-tips, 10k stars), Setup Pre Commit (fossasia/eventyay-interpretation, 1.6k stars) and Bun Runtime (spinspire/pocketbase-sveltekit-starter, 511 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
express-validator (a GitHub organization) maintains it in express-validator/express-validator, which has 6,233 GitHub stars. The repository was last updated on October 3, 2026.
Source: express-validator/express-validator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.