Dependency Update Bot
Varnan-Tech/opendirectory
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR.
$ npx skills add joshukraine/dotfiles --skill update-deps -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install joshukraine/dotfiles update-deps --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/joshukraine/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude/.claude/skills/update-deps .claude/skills/update-deps && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "update-deps" agent skill from https://github.com/joshukraine/dotfiles/tree/master/claude/.claude/skills/update-deps into .claude/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/joshukraine/dotfiles/tree/master/claude/.claude/skills/update-depsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add joshukraine/dotfiles --skill update-deps -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install joshukraine/dotfiles update-deps --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/joshukraine/dotfiles.git skills-src && mkdir -p .agents/skills && cp -r skills-src/claude/.claude/skills/update-deps .agents/skills/update-deps && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "update-deps" agent skill from https://github.com/joshukraine/dotfiles/tree/master/claude/.claude/skills/update-deps into .agents/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add joshukraine/dotfiles --skill update-deps -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install joshukraine/dotfiles update-deps --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/joshukraine/dotfiles.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/claude/.claude/skills/update-deps .cursor/skills/update-deps && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "update-deps" agent skill from https://github.com/joshukraine/dotfiles/tree/master/claude/.claude/skills/update-deps into .cursor/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/joshukraine/dotfiles.git --path claude/.claude/skills/update-deps--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add joshukraine/dotfiles --skill update-deps -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install joshukraine/dotfiles update-deps --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/joshukraine/dotfiles.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/claude/.claude/skills/update-deps .gemini/skills/update-deps && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "update-deps" agent skill from https://github.com/joshukraine/dotfiles/tree/master/claude/.claude/skills/update-deps into .gemini/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install joshukraine/dotfiles update-depsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add joshukraine/dotfiles --skill update-deps -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/joshukraine/dotfiles.git skills-src && mkdir -p .github/skills && cp -r skills-src/claude/.claude/skills/update-deps .github/skills/update-deps && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "update-deps" agent skill from https://github.com/joshukraine/dotfiles/tree/master/claude/.claude/skills/update-deps into .github/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add joshukraine/dotfiles --skill update-deps -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install joshukraine/dotfiles update-deps --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/joshukraine/dotfiles.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/claude/.claude/skills/update-deps .opencode/skills/update-deps && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "update-deps" agent skill from https://github.com/joshukraine/dotfiles/tree/master/claude/.claude/skills/update-deps into .opencode/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
update-depsDependabot-aware dependency updates with security audit, real-CI validation, and a unified PR.
Update Deps is an agent skill from joshukraine/dotfiles. Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR. Framework-agnostic.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management and Security review. It works with npm. The repository describes itself as: :roundpushpin: My dotfiles for macOS using Neovim, Zsh, and Ghostty + Tmux. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b59ad5b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghnpmcargobundlepoetrygopipyarnpnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, npm, pip, yarn and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Update Deps loads about 2.2k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 1,065 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from joshukraine/dotfiles at commit b59ad5b, republished under its MIT licence (© joshukraine). 1,065 words, ~2,192 tokens.
.claude/skills/update-deps/SKILL.md (or your agent's skills folder).Update project dependencies safely: reconcile open Dependabot PRs into one unified change, run the project's security audit, validate boot-affecting changes against the real CI environment, and open a single PR — instead of stopping at local commits.
This skill is framework-agnostic. It detects the project's package manager, test/lint commands, audit suite, and CI workflow rather than assuming a stack.
--dry-run: Show what would be updated without making changes--major: Include major version updates (default: minor/patch only)--package <name>: Update specific package only--skip-tests: Skip running tests between updatesDetect → Reconcile Dependabot → Update → Audit → Validate on real CI → Open PR → Verify auto-closeEach stage feeds the next. Don't skip the audit or the real-CI validation for boot-affecting changes — those are the two stages that catch what local tests can't.
Detect both the package manager and the project's real entry points. The runners below are common defaults, not assumptions — always confirm against what the repo actually uses.
package.json (npm/yarn/pnpm) — check the lockfile to disambiguateGemfile (bundler)requirements.txt / pyproject.toml (pip/poetry/uv)Cargo.toml (cargo)go.mod (go modules)bin/ci, bin/test, script/test, or a Makefile/Justfile target is the canonical gate — use it if present.tsc, mypy, etc..github/workflows/*.yml and identify the workflow that runs on the default branch and the jobs it contains.Before making any changes, find out what Dependabot already has in flight:
gh pr list --app dependabot --state open --json number,title,headRefName,bodyKeep the safe, category-by-category loop:
--major. Isolate a risky major into its own commit — or its own PR — so it can be rolled back cleanly without reverting the safe bumps.--skip-tests: skip test execution.require:), a renamed config key. These are where "the tests pass but boot breaks" lives.This is the highest-value stage on a dependency PR — not an afterthought. After updates, run the project's detected audit suite and fold any newly surfaced fix into this PR (a fresh advisory is in-scope, not a separate task):
| Ecosystem | Audit tools (detect what's present) |
|---|---|
| Ruby | bundler-audit; plus brakeman and importmap audit on Rails |
| Node | npm audit, yarn npm audit, pnpm audit |
| Python | pip-audit, safety |
| Rust | cargo audit |
| Go | govulncheck |
If the project's CI gate (e.g. bin/ci) already runs these, run that gate rather than invoking each tool separately.
A change that touches the manifest (the Gemfile, package.json, pyproject.toml — not just the lockfile) can alter what loads at boot. Local gates cannot catch a failure caused by a system library that happens to be installed on the dev machine but missing on one CI job. Validate those changes on the actual CI environment before recommending merge:
gh workflow run <ci-workflow> --ref <branch>
gh run watch # or: gh run list --branch <branch>Do this when:
require:/load behavior, version constraint change), and/orLockfile-only patch bumps with a green local gate generally don't need a dedicated CI run.
Stop-at-commits is not the finish line. Open one PR for the reconciled set, following the project's PR conventions — hand off to the /create-pr skill (it generates the description, links issues, and updates the ROADMAP). Summarize in the PR body: the bumps grouped by category, the Dependabot PRs this supersedes, any CVE fixed, and the result of the real-CI run.
After the PR merges, expect Dependabot to auto-close the superseded PRs on its own — verify it did rather than pre-emptively closing them:
gh pr list --app dependabot --state opendependabot/dependabot-core#13606) — close it manually with a note. Don't duplicate Dependabot's behavior or race its rebase.The lessons this workflow encodes, worth keeping in mind when a situation doesn't fit the steps above:
npm outdated # check
npm update <pkg> # updatebundle outdated
bundle update <gem>pip list --outdated
poetry show --outdated && poetry update <pkg>cargo outdated
cargo update <pkg>go list -u -m all
go get -u <pkg>1.2.3 → 1.2.4.1.2.3 → 1.3.0.--major) — breaking changes, e.g. 1.2.3 → 2.0.0. Isolate for clean rollback.Use Conventional Commits format from global CLAUDE.md:
chore(deps): update dependencies
Security updates:
- erb: 6.0.1 → 6.0.3 (CVE-2026-41316)
Patch updates:
- rails: 7.1.3 → 7.1.5
Minor updates:
- image_processing: 1.12 → 2.0
Breaking changes:
- image_processing 2.0 requires ruby-vips; added with require: false
so a missing libvips does not crash boot.Follow dependency best practices from global CLAUDE.md:
© joshukraine, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in claude/.claude/skills/update-deps of joshukraine/dotfiles.
Open the folder on GitHubat commit b59ad5b
Update Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Update Deps this skilljoshukraine/dotfiles | 429 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Dependency Update BotVarnan-Tech/opendirectory | 674 | — | ~3k | Automated safety check: Notes | MIT | |
| JS Security Auditc0x12c/ai-toolkit | 106 | — | ~1.6k | Automated safety check: Warn | None | |
| Verdaccio Code Reviewverdaccio/verdaccio | 18k | — | ~853 | Automated safety check: Pass | MIT | |
| Stash Supply Chain Securitycipherstash/stack | 157 | — | ~5.2k | Automated safety check: Warn | MIT | |
| Dependency Upgrade Protocoldralgorhythm/claude-agentic-framework | 125 | — | ~1.5k | Automated safety check: Pass | None |
Varnan-Tech/opendirectory
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
c0x12c/ai-toolkit
Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
cipherstash/stack
Supply-chain security controls for the @cipherstash/stack monorepo.
dralgorhythm/claude-agentic-framework
Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.
mukul975/Anthropic-Cybersecurity-Skills
Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem…
joshukraine/dotfiles
Manage Todoist tasks, projects, labels, filters, sections, comments, reminders, and workspaces via the td CLI.
joshukraine/dotfiles
Vet open issues for autonomous resolution and queue the qualifying ones with the autopilot-queued label — the start-of-day "fill the queue" half of the triage → run split.
joshukraine/dotfiles
Quick 2-minute status update on current phase, completed work, blockers, and health check.
joshukraine/dotfiles
Create a pull request with auto-generated description, issue linking, ROADMAP updates, and PR-metadata validation.
joshukraine/dotfiles
Detailed technical walkthrough covering architecture, test coverage, product tour, and key design decisions.
joshukraine/dotfiles
Pre-PR advisory check for deviations from the project spec. An agent skill from joshukraine/dotfiles.
Works with
Categories
Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR. Update Deps is an agent skill from joshukraine/dotfiles. Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR.
Update Deps fits situations like: tasks that involve Dependency management; tasks that involve Security review.
Run `npx skills add joshukraine/dotfiles --skill update-deps -a claude-code`. Or copy the skill folder (claude/.claude/skills/update-deps in joshukraine/dotfiles) into .claude/skills/update-deps in your project. Claude Code loads it when a task matches its description.
Run `npx skills add joshukraine/dotfiles --skill update-deps -a codex`. Or copy the skill folder (claude/.claude/skills/update-deps in joshukraine/dotfiles) into .agents/skills/update-deps in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add joshukraine/dotfiles --skill update-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-deps, .gemini/skills/update-deps, .github/skills/update-deps and .opencode/skills/update-deps in your project.
Going by SKILL.md and its folder, Update Deps needs the command-line tools its instructions call (gh, npm, cargo, bundle, poetry and go). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use gh, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Update Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Update Deps: Dependency Update Bot (Varnan-Tech/opendirectory, 674 stars), JS Security Audit (c0x12c/ai-toolkit, 106 stars), Verdaccio Code Review (verdaccio/verdaccio, 18k stars) and Stash Supply Chain Security (cipherstash/stack, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
joshukraine (a GitHub user) maintains it in joshukraine/dotfiles, which has 429 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.
Source: joshukraine/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.