Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
Install the "dependabot-alerts-update" agent skill from https://github.com/livesession/xyd/tree/master/.claude/skills/dependabot-alerts-update into .claude/skills/dependabot-alerts-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-alerts-update", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add livesession/xyd --skill dependabot-alerts-update -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "dependabot-alerts-update" agent skill from https://github.com/livesession/xyd/tree/master/.claude/skills/dependabot-alerts-update into .agents/skills/dependabot-alerts-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-alerts-update", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add livesession/xyd --skill dependabot-alerts-update -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "dependabot-alerts-update" agent skill from https://github.com/livesession/xyd/tree/master/.claude/skills/dependabot-alerts-update into .cursor/skills/dependabot-alerts-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-alerts-update", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add livesession/xyd --skill dependabot-alerts-update -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "dependabot-alerts-update" agent skill from https://github.com/livesession/xyd/tree/master/.claude/skills/dependabot-alerts-update into .gemini/skills/dependabot-alerts-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-alerts-update", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add livesession/xyd --skill dependabot-alerts-update -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "dependabot-alerts-update" agent skill from https://github.com/livesession/xyd/tree/master/.claude/skills/dependabot-alerts-update into .github/skills/dependabot-alerts-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-alerts-update", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add livesession/xyd --skill dependabot-alerts-update -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "dependabot-alerts-update" agent skill from https://github.com/livesession/xyd/tree/master/.claude/skills/dependabot-alerts-update into .opencode/skills/dependabot-alerts-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-alerts-update", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
dependabot-alerts-update
GitHub stars
114
Token cost
~2k tokens
SKILL.md length
705 words
Files
2 (incl. scripts)
Skills in repo
1
Repo updated
First seen
Licence
MIT
At a glance
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
Works in 6 steps: Fetch Dependabot Alerts → Parse and Categorize Alerts → Research Secure Versions → …
User mentions Dependabot alerts
SKILL.md covers Workflow, Implementation, Common Vulnerabilities and Fixes and Error Handling, plus 2 more sections
Runs JavaScript scripts from its folder; calls pnpm, gh and node; reaches github.com and security.snyk.io; needs GITHUB_TOKEN
What it does
Dependabot Alerts Update is an agent skill from livesession/xyd. Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files across monorepo workspaces. Use when user mentions Dependabot alerts, security vulnerabilities, or wants to update vulnerable dependencies automatically.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.
It sits in Development, covering Dependency management, Monorepo tooling and Vulnerability scanning. It works with npm, GitHub, OpenAPI and React. The repository describes itself as: ambitious docs framework for everyone. The licence is MIT.
When your agent uses it
User mentions Dependabot alerts
Security vulnerabilities
Wants to update vulnerable dependencies automatically
Example prompts
“/dependabot-alerts-update”
Requirements
Python 3
Node.js
A credential in GITHUB_TOKEN
Workflow steps
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0167722. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
pnpm
gh
node
npm
yarn
git
curl
jq
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
github.com
security.snyk.io
api.github.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKEN
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Dependabot Alerts Update loads about 2k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 705 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~93
When it runs· the whole SKILL.md, loaded when a task matches
~2k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Download SKILL.mdSave it as .claude/skills/dependabot-alerts-update/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
dependabot-alerts-update
description
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files across monorepo workspaces. Use when user mentions Dependabot alerts, security vulnerabilities, or wants to update vulnerable dependencies automatically.
Dependabot Alerts Update
Automatically fetch Dependabot security alerts from GitHub and update vulnerable packages to secure versions.
Workflow
1. Fetch Dependabot Alerts
Use GitHub REST API to fetch open Dependabot alerts:
bash
# Get repository owner and name from git remote
git remote get-url origin
# Fetch alerts (requires GITHUB_TOKEN)
curl -H "Authorization: token $GITHUB_TOKEN" \
-H "Accept: application/vnd.github+json" \
"https://api.github.com/repos/{owner}/{repo}/dependabot/alerts?state=open"
Or use the GitHub CLI if available:
bash
gh api repos/{owner}/{repo}/dependabot/alerts --jq '.[] | select(.state == "open")'
Required environment variable: GITHUB_TOKEN with security_events scope.
Direct dependencies: Update version in package.json
Transitive dependencies: Update parent package that brings in the vulnerable dependency
Workspace dependencies: Update in root or specific workspace package
Update Pattern
For each vulnerable package found in package.json:
json
// Before
"package-name": "^1.2.3"
// After (if 1.5.0 fixes the vulnerability)
"package-name": "^1.5.0"
Use ^ prefix to allow patch/minor updates unless major version is required.
Monorepo Considerations
pnpm workspaces: Update in the specific workspace package.json
npm workspaces: Same approach
Lerna: Update in individual package.json files
Root dependencies: Update root package.json if used across workspaces
5. Handle Special Cases
Multiple Versions of Same Package
If the same package appears in multiple package.json files with different versions:
Update all instances to the same secure version
Ensure compatibility across workspaces
Peer Dependencies
For peer dependencies, update the package that provides the dependency, not the peer dependency declaration itself.
Lock Files
After updating package.json:
pnpm: Run pnpm install to update pnpm-lock.yaml
npm: Run npm install to update package-lock.json
yarn: Run yarn install to update yarn.lock
Note: Some example directories may have separate lock files that need individual updates.
6. Verification
After updates:
Check remaining alerts:
bash
gh api repos/{owner}/{repo}/dependabot/alerts?state=open
Run audit:
bash
pnpm audit # or npm audit / yarn audit
Test build:
bash
pnpm run build
Implementation
Using the Script
A Node.js script is provided in scripts/fetch_and_fix_alerts.mjs that automates the workflow:
bash
# Set GitHub token
export GITHUB_TOKEN=your_token_here
# Dry run to see what would be updated
node scripts/fetch_and_fix_alerts.mjs --dry-run
# Actually update packages
node scripts/fetch_and_fix_alerts.mjs
# Or specify repo explicitly
node scripts/fetch_and_fix_alerts.mjs --owner OWNER --repo REPO --token TOKEN
The script:
Auto-detects repository from git remote
Fetches all open Dependabot alerts
Finds packages in package.json files
Updates versions (uses first_patched_version from API when available)
Preserves version prefixes (^, ~)
Requirements: Node.js 18+ (uses native fetch API, no external dependencies)
Show full SKILL.md (269 more words)Show less
Manual Implementation
If implementing manually or the script needs customization:
python
# Pseudocode workflow
alerts = fetch_dependabot_alerts(owner, repo, token)
vulnerable_packages = parse_alerts(alerts)
for package in vulnerable_packages:
secure_version = research_secure_version(package, cve_id)
package_json_files = find_package_json_with_package(package)
for pkg_json in package_json_files:
update_package_version(pkg_json, package, secure_version)
run_package_manager_install()
verify_alerts_resolved()
js-yaml: Update to 4.1.1+ (prototype pollution fix)
@modelcontextprotocol/sdk: Update to 1.25.2+ (ReDoS fix)
langchain: Update to 1.2.3+ (serialization injection fix)
storybook: Update to 8.6.15+ (environment variable exposure fix)
Transitive Dependencies
Many vulnerabilities (h3, qs, tar-fs, node-forge, glob, jws, ipx, tar, esbuild, http-proxy-middleware, undici, on-headers, tmp, diff) are transitive and will be resolved when direct dependencies are updated.
Error Handling
API rate limits: Implement exponential backoff for GitHub API calls
Missing GITHUB_TOKEN: Prompt user to set token or use GitHub CLI authentication
Package not found: Skip and log warning
Version conflicts: Report conflicts and suggest manual resolution
Build failures: Rollback changes if build fails after updates
Output
After processing, provide a summary listing:
All alerts processed (grouped by severity)
Packages updated with old → new versions
Files modified
Transitive dependencies that should be resolved automatically
Remaining alerts (if any that couldn't be auto-fixed)
Dependabot Alerts Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Dependabot Alerts Update compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Dependabot Alerts Update this skilllivesession/xyd
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.
A skill your agent uses whenever a plugin under plugins/<name is updated/pushed, or whenever asked to write a changelog/release for the app or a plugin.
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…. Dependabot Alerts Update is an agent skill from livesession/xyd.json files across monorepo workspaces.
When should I use Dependabot Alerts Update?
Dependabot Alerts Update fits situations like: user mentions Dependabot alerts; security vulnerabilities; wants to update vulnerable dependencies automatically.
How do I install Dependabot Alerts Update in Claude Code?
Run `npx skills add livesession/xyd --skill dependabot-alerts-update -a claude-code`. Or copy the skill folder (.claude/skills/dependabot-alerts-update in livesession/xyd) into .claude/skills/dependabot-alerts-update in your project. Claude Code loads it when a task matches its description.
How do I install Dependabot Alerts Update in Codex?
Run `npx skills add livesession/xyd --skill dependabot-alerts-update -a codex`. Or copy the skill folder (.claude/skills/dependabot-alerts-update in livesession/xyd) into .agents/skills/dependabot-alerts-update in your project. Codex loads it when a task matches its description.
Can I use Dependabot Alerts Update in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add livesession/xyd --skill dependabot-alerts-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-alerts-update, .gemini/skills/dependabot-alerts-update, .github/skills/dependabot-alerts-update and .opencode/skills/dependabot-alerts-update in your project.
What does Dependabot Alerts Update need to run?
Going by SKILL.md and its folder, Dependabot Alerts Update needs JavaScript for the scripts in its folder, the command-line tools its instructions call (pnpm, gh, node, npm, yarn and git) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; Node.js; A credential in GITHUB_TOKEN.
Does Dependabot Alerts Update access the network?
SKILL.md names 3 domains. In commands or code: github.com, security.snyk.io and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Is Dependabot Alerts Update safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
What licence does Dependabot Alerts Update use?
Dependabot Alerts Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Dependabot Alerts Update use?
About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Dependabot Alerts Update?
Skills that share tags, products or a category with Dependabot Alerts Update: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Fix Security PR (unional/typescript-blackbook, 133 stars), Fix Dependabot (owid/etl, 159 stars) and Plugin Release Check (VoidenHQ/voiden, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Dependabot Alerts Update?
livesession (a GitHub organization) maintains it in livesession/xyd, which has 114 GitHub stars. The repository was last updated on October 8, 2026.
Source: livesession/xyd on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.