Agent skill

Dependabot Alerts Update

by livesession in livesession/xyd

Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

MITAuto-check passedDevelopment

Install Dependabot Alerts Update

skills CLI
$ npx skills add livesession/xyd --skill dependabot-alerts-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install livesession/xyd dependabot-alerts-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/livesession/xyd.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dependabot-alerts-update .claude/skills/dependabot-alerts-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependabot-alerts-update
GitHub stars
114
Token cost
~2k tokens
SKILL.md length
705 words
Files
2 (incl. scripts)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

  • Works in 6 steps: Fetch Dependabot Alerts → Parse and Categorize Alerts → Research Secure Versions → …
  • User mentions Dependabot alerts
  • SKILL.md covers Workflow, Implementation, Common Vulnerabilities and Fixes and Error Handling, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls pnpm, gh and node; reaches github.com and security.snyk.io; needs GITHUB_TOKEN

What it does

Dependabot Alerts Update is an agent skill from livesession/xyd. Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files across monorepo workspaces. Use when user mentions Dependabot alerts, security vulnerabilities, or wants to update vulnerable dependencies automatically.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.

It sits in Development, covering Dependency management, Monorepo tooling and Vulnerability scanning. It works with npm, GitHub, OpenAPI and React. The repository describes itself as: ambitious docs framework for everyone. The licence is MIT.

When your agent uses it

  • User mentions Dependabot alerts
  • Security vulnerabilities
  • Wants to update vulnerable dependencies automatically

Example prompts

  • “/dependabot-alerts-update”

Requirements

  • Python 3
  • Node.js
  • A credential in GITHUB_TOKEN

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Fetch Dependabot Alerts
  2. Parse and Categorize Alerts
  3. Research Secure Versions
  4. Update package.json Files
  5. Handle Special Cases
  6. Verification

What it can do on your machine

Read from SKILL.md and the folder at commit 0167722. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • pnpm
    • gh
    • node
    • npm
    • yarn
    • git
    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • security.snyk.io
    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependabot Alerts Update loads about 2k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 705 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from livesession/xyd at commit 0167722, republished under its MIT licence (© livesession). 705 words, ~2,046 tokens.

Download SKILL.mdSave it as .claude/skills/dependabot-alerts-update/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
dependabot-alerts-update
description
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files across monorepo workspaces. Use when user mentions Dependabot alerts, security vulnerabilities, or wants to update vulnerable dependencies automatically.

Dependabot Alerts Update

Automatically fetch Dependabot security alerts from GitHub and update vulnerable packages to secure versions.

Workflow

1. Fetch Dependabot Alerts

Use GitHub REST API to fetch open Dependabot alerts:

bash
# Get repository owner and name from git remote
git remote get-url origin

# Fetch alerts (requires GITHUB_TOKEN)
curl -H "Authorization: token $GITHUB_TOKEN" \
  -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{owner}/{repo}/dependabot/alerts?state=open"

Or use the GitHub CLI if available:

bash
gh api repos/{owner}/{repo}/dependabot/alerts --jq '.[] | select(.state == "open")'

Required environment variable: GITHUB_TOKEN with security_events scope.

2. Parse and Categorize Alerts

For each alert, extract:

  • Package name (dependency.package.name)
  • Severity (security_advisory.severity: critical, high, moderate, low)
  • Vulnerable versions (security_vulnerability.vulnerable_version_range)
  • CVE/GHSA ID (security_advisory.ghsa_id or security_advisory.cve_id)
  • Manifest path (dependency.manifest_path)

Group alerts by:

  1. Direct dependencies (in package.json files)
  2. Transitive dependencies (will be resolved via direct dependency updates)
  3. Severity (prioritize critical/high first)
3. Research Secure Versions

For each vulnerable package, determine the minimum secure version:

  1. Check alert API response - The security_vulnerability.first_patched_version field often contains the fixed version:

    bash
    gh api repos/{owner}/{repo}/dependabot/alerts/{alert_number} | jq '.security_vulnerability.first_patched_version'
  2. Search for security advisories:

    • GitHub Security Advisories: https://github.com/advisories?query={package}
    • npm security: npm audit {package}
    • Snyk: https://security.snyk.io/package/npm/{package}
  3. Web search for CVE details and fixed versions:

    • Search: {package} {CVE_ID} fixed version
    • Search: {package} {GHSA_ID} fixed version
    • Check package changelog/release notes
  4. Verify compatibility:

    • Check if secure version is compatible with current version range
    • Consider breaking changes in major version updates
    • For peer dependencies, ensure the providing package is updated
4. Update package.json Files
Identify All package.json Files

For monorepos, find all package.json files:

bash
find . -name "package.json" -not -path "*/node_modules/*" -not -path "*/.git/*"
Update Strategy
  1. Direct dependencies: Update version in package.json
  2. Transitive dependencies: Update parent package that brings in the vulnerable dependency
  3. Workspace dependencies: Update in root or specific workspace package
Update Pattern

For each vulnerable package found in package.json:

json
// Before
"package-name": "^1.2.3"

// After (if 1.5.0 fixes the vulnerability)
"package-name": "^1.5.0"

Use ^ prefix to allow patch/minor updates unless major version is required.

Monorepo Considerations
  • pnpm workspaces: Update in the specific workspace package.json
  • npm workspaces: Same approach
  • Lerna: Update in individual package.json files
  • Root dependencies: Update root package.json if used across workspaces
5. Handle Special Cases
Multiple Versions of Same Package

If the same package appears in multiple package.json files with different versions:

  • Update all instances to the same secure version
  • Ensure compatibility across workspaces
Peer Dependencies

For peer dependencies, update the package that provides the dependency, not the peer dependency declaration itself.

Lock Files

After updating package.json:

  • pnpm: Run pnpm install to update pnpm-lock.yaml
  • npm: Run npm install to update package-lock.json
  • yarn: Run yarn install to update yarn.lock

Note: Some example directories may have separate lock files that need individual updates.

6. Verification

After updates:

  1. Check remaining alerts:

    bash
    gh api repos/{owner}/{repo}/dependabot/alerts?state=open
  2. Run audit:

    bash
    pnpm audit  # or npm audit / yarn audit
  3. Test build:

    bash
    pnpm run build

Implementation

Using the Script

A Node.js script is provided in scripts/fetch_and_fix_alerts.mjs that automates the workflow:

bash
# Set GitHub token
export GITHUB_TOKEN=your_token_here

# Dry run to see what would be updated
node scripts/fetch_and_fix_alerts.mjs --dry-run

# Actually update packages
node scripts/fetch_and_fix_alerts.mjs

# Or specify repo explicitly
node scripts/fetch_and_fix_alerts.mjs --owner OWNER --repo REPO --token TOKEN

The script:

  1. Auto-detects repository from git remote
  2. Fetches all open Dependabot alerts
  3. Finds packages in package.json files
  4. Updates versions (uses first_patched_version from API when available)
  5. Preserves version prefixes (^, ~)

Requirements: Node.js 18+ (uses native fetch API, no external dependencies)

Show full SKILL.md (269 more words)Show less
Manual Implementation

If implementing manually or the script needs customization:

python
# Pseudocode workflow
alerts = fetch_dependabot_alerts(owner, repo, token)
vulnerable_packages = parse_alerts(alerts)

for package in vulnerable_packages:
    secure_version = research_secure_version(package, cve_id)
    package_json_files = find_package_json_with_package(package)
    
    for pkg_json in package_json_files:
        update_package_version(pkg_json, package, secure_version)

run_package_manager_install()
verify_alerts_resolved()

Common Vulnerabilities and Fixes

Critical/High Priority
  • happy-dom: Update vitest to latest (includes happy-dom@20.0.2+)
  • react-router: Update to 7.5.2+ for security fixes
  • js-yaml: Update to 4.1.1+ (prototype pollution fix)
  • @modelcontextprotocol/sdk: Update to 1.25.2+ (ReDoS fix)
  • langchain: Update to 1.2.3+ (serialization injection fix)
  • storybook: Update to 8.6.15+ (environment variable exposure fix)
Transitive Dependencies

Many vulnerabilities (h3, qs, tar-fs, node-forge, glob, jws, ipx, tar, esbuild, http-proxy-middleware, undici, on-headers, tmp, diff) are transitive and will be resolved when direct dependencies are updated.

Error Handling

  • API rate limits: Implement exponential backoff for GitHub API calls
  • Missing GITHUB_TOKEN: Prompt user to set token or use GitHub CLI authentication
  • Package not found: Skip and log warning
  • Version conflicts: Report conflicts and suggest manual resolution
  • Build failures: Rollback changes if build fails after updates

Output

After processing, provide a summary listing:

  • All alerts processed (grouped by severity)
  • Packages updated with old → new versions
  • Files modified
  • Transitive dependencies that should be resolved automatically
  • Remaining alerts (if any that couldn't be auto-fixed)
  • Next steps:
    1. Run package manager install: pnpm install (or npm install / yarn install)
    2. Verify with audit: pnpm audit
    3. Test build: pnpm run build
    4. Check remaining alerts in GitHub

GitHub API Authentication

The script requires a GitHub token with security_events scope:

  1. Create a Personal Access Token:

    • Go to GitHub Settings → Developer settings → Personal access tokens → Tokens (classic)
    • Generate new token with security_events scope
    • Or use Fine-grained token with "Read Dependabot alerts" permission
  2. Set the token:

    bash
    export GITHUB_TOKEN=your_token_here
  3. Or use GitHub CLI (alternative):

    bash
    gh auth login
    # Then use: gh api repos/{owner}/{repo}/dependabot/alerts

© livesession, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in .claude/skills/dependabot-alerts-update of livesession/xyd.

  • SKILL.md
  • scripts/fetch_and_fix_alerts.mjs

Open the folder on GitHubat commit 0167722

Compare with similar skills

Dependabot Alerts Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependabot Alerts Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependabot Alerts Update this skilllivesession/xyd114—~2kAutomated safety check: PassMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Fix Security PRunional/typescript-blackbook133—~1.4kAutomated safety check: WarnMIT
Fix Dependabotowid/etl159—~2.8kAutomated safety check: PassMIT
Plugin Release CheckVoidenHQ/voiden1.8k—~857Automated safety check: PassApache-2.0
Create Releaselablup/backend.ai-webui133—~1.5kAutomated safety check: PassLGPL-3.0

Similar skills

  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Fix Security PR

    unional/typescript-blackbook

    Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

    133 GitHub stars~1.4k tokensUpdated 2 days ago
    DevelopmentAuto-check: warnings
  • Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.

    159 GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Plugin Release Check

    VoidenHQ/voiden

    A skill your agent uses whenever a plugin under plugins/<name is updated/pushed, or whenever asked to write a changelog/release for the app or a plugin.

    1.8k GitHub stars~857 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Create Release

    lablup/backend.ai-webui

    Create a release branch, tag, and GitHub release for Backend.AI WebUI.

    133 GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Workspace

    alinaqi/maggy

    Dynamic multi-repo and monorepo awareness for Claude Code. An agent skill from alinaqi/maggy.

    707 GitHub stars~7.3k tokensUpdated 16 days ago
    DevelopmentAuto-check passed

Questions about Dependabot Alerts Update

What does Dependabot Alerts Update do?

Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…. Dependabot Alerts Update is an agent skill from livesession/xyd.json files across monorepo workspaces.

When should I use Dependabot Alerts Update?

Dependabot Alerts Update fits situations like: user mentions Dependabot alerts; security vulnerabilities; wants to update vulnerable dependencies automatically.

How do I install Dependabot Alerts Update in Claude Code?

Run `npx skills add livesession/xyd --skill dependabot-alerts-update -a claude-code`. Or copy the skill folder (.claude/skills/dependabot-alerts-update in livesession/xyd) into .claude/skills/dependabot-alerts-update in your project. Claude Code loads it when a task matches its description.

How do I install Dependabot Alerts Update in Codex?

Run `npx skills add livesession/xyd --skill dependabot-alerts-update -a codex`. Or copy the skill folder (.claude/skills/dependabot-alerts-update in livesession/xyd) into .agents/skills/dependabot-alerts-update in your project. Codex loads it when a task matches its description.

Can I use Dependabot Alerts Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add livesession/xyd --skill dependabot-alerts-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-alerts-update, .gemini/skills/dependabot-alerts-update, .github/skills/dependabot-alerts-update and .opencode/skills/dependabot-alerts-update in your project.

What does Dependabot Alerts Update need to run?

Going by SKILL.md and its folder, Dependabot Alerts Update needs JavaScript for the scripts in its folder, the command-line tools its instructions call (pnpm, gh, node, npm, yarn and git) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; Node.js; A credential in GITHUB_TOKEN.

Does Dependabot Alerts Update access the network?

SKILL.md names 3 domains. In commands or code: github.com, security.snyk.io and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Dependabot Alerts Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dependabot Alerts Update use?

Dependabot Alerts Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependabot Alerts Update use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependabot Alerts Update?

Skills that share tags, products or a category with Dependabot Alerts Update: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Fix Security PR (unional/typescript-blackbook, 133 stars), Fix Dependabot (owid/etl, 159 stars) and Plugin Release Check (VoidenHQ/voiden, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependabot Alerts Update?

livesession (a GitHub organization) maintains it in livesession/xyd, which has 114 GitHub stars. The repository was last updated on October 8, 2026.

Source: livesession/xyd on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.