Uv Workflow
Aedelon/claude-code-blueprint
Master uv package manager for Python: project setup, dependency management, virtual environments, lockfiles, CI/CD integration, Docker builds, and migration from pip/poetry.
Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…
$ npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ossf/oss-crs sync-dependabot-app-deps --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ossf/oss-crs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sync-dependabot-app-deps .claude/skills/sync-dependabot-app-deps && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sync-dependabot-app-deps" agent skill from https://github.com/ossf/oss-crs/tree/main/.claude/skills/sync-dependabot-app-deps into .claude/skills/sync-dependabot-app-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-dependabot-app-deps", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ossf/oss-crs/tree/main/.claude/skills/sync-dependabot-app-depsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ossf/oss-crs sync-dependabot-app-deps --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ossf/oss-crs.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/sync-dependabot-app-deps .agents/skills/sync-dependabot-app-deps && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sync-dependabot-app-deps" agent skill from https://github.com/ossf/oss-crs/tree/main/.claude/skills/sync-dependabot-app-deps into .agents/skills/sync-dependabot-app-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-dependabot-app-deps", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ossf/oss-crs sync-dependabot-app-deps --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ossf/oss-crs.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/sync-dependabot-app-deps .cursor/skills/sync-dependabot-app-deps && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sync-dependabot-app-deps" agent skill from https://github.com/ossf/oss-crs/tree/main/.claude/skills/sync-dependabot-app-deps into .cursor/skills/sync-dependabot-app-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-dependabot-app-deps", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ossf/oss-crs.git --path .claude/skills/sync-dependabot-app-deps--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ossf/oss-crs sync-dependabot-app-deps --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ossf/oss-crs.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/sync-dependabot-app-deps .gemini/skills/sync-dependabot-app-deps && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sync-dependabot-app-deps" agent skill from https://github.com/ossf/oss-crs/tree/main/.claude/skills/sync-dependabot-app-deps into .gemini/skills/sync-dependabot-app-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-dependabot-app-deps", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ossf/oss-crs sync-dependabot-app-depsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ossf/oss-crs.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/sync-dependabot-app-deps .github/skills/sync-dependabot-app-deps && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sync-dependabot-app-deps" agent skill from https://github.com/ossf/oss-crs/tree/main/.claude/skills/sync-dependabot-app-deps into .github/skills/sync-dependabot-app-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-dependabot-app-deps", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ossf/oss-crs sync-dependabot-app-deps --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ossf/oss-crs.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/sync-dependabot-app-deps .opencode/skills/sync-dependabot-app-deps && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sync-dependabot-app-deps" agent skill from https://github.com/ossf/oss-crs/tree/main/.claude/skills/sync-dependabot-app-deps into .opencode/skills/sync-dependabot-app-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sync-dependabot-app-deps", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sync-dependabot-app-depsRead every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…
Sync Dependabot App Deps is an agent skill from ossf/oss-crs. Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt, pyproject.toml, uv.lock, package.json, package-lock.json/yarn.lock/pnpm-lock.yaml) without merging the PRs.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management. It works with npm, Python, pnpm and Docker. The repository describes itself as: Cyber Reasoning Systems for Bug-Finding and Patching in Open Source Software. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4037c51. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBashEditFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghpythonuvnpmyarnpnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, gh, uv, npm, yarn and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sync Dependabot App Deps loads about 1.7k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 721 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Bash, EditAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ossf/oss-crs at commit 4037c51, republished under its MIT licence (© ossf). 721 words, ~1,683 tokens.
.claude/skills/sync-dependabot-app-deps/SKILL.md (or your agent's skills folder).Dependabot opens one PR per application-code dependency bump across several
directories (Python: /, /oss-crs-infra/builder-sidecar,
/oss-crs-infra/runner-sidecar, /oss-crs-infra/lifecycle,
/oss-crs-infra/litellm-key-gen; JS: /site and any other npm package — see
.github/dependabot.yml). This skill collects all the open Python and JS
PRs and applies their changes directly to the local working tree, so the
bumps land in one local change set instead of N separate merges.
The reliable signal for "this PR is an app-dep bump" is the branch name prefix:
dependabot/pip/ — used for plain requirements.txt directoriesdependabot/uv/ — used for the root project that ships a uv.lockdependabot/npm_and_yarn/Both Python prefixes must be matched. Dependabot picks uv/ over pip/ for any
directory where it detects a uv.lock, regardless of how the directory is
declared in .github/dependabot.yml. Missing dependabot/uv/ silently drops
the root project's PRs.
GitHub Actions (dependabot/github_actions/) and Docker (dependabot/docker/)
PRs are excluded — leave them alone (Docker has its own skill,
sync-dependabot-pins).
Make sure the working tree is clean first (git status --short); if there are
uncommitted changes, stop and ask the user how to proceed rather than pulling
over them. Then update main and cut a dated working branch so the carried-over
bumps land in one reviewable branch:
git checkout main
git pull
git checkout -b "chore/app-deps-dependabot-$(date +%Y-%m-%d)"If the branch already exists (the skill was run earlier today), switch to it
instead: git checkout "chore/app-deps-dependabot-$(date +%Y-%m-%d)".
gh pr list --author "app/dependabot" --state open --limit 100 \
--json number,title,headRefName \
--jq '.[] | select(.headRefName | startswith("dependabot/pip/") or startswith("dependabot/uv/") or startswith("dependabot/npm_and_yarn/")) | "\(.number)\t\(.headRefName)\t\(.title)"'If this prints nothing, there are no open Python or JS Dependabot PRs — stop and tell the user there is nothing to sync.
Otherwise, list the matched PR numbers to the user before applying so they know what is about to change. It is helpful to group them by ecosystem (pip vs npm_and_yarn) in the report.
For each matched PR number N, apply its diff with a 3-way merge. --3way lets
two PRs that touch the same file (e.g. one bumps uvicorn, another bumps
python-multipart in the same requirements.txt; or two npm bumps that both
touch package-lock.json) both land cleanly, and it correctly carries
generated lockfile changes (uv.lock, package-lock.json, yarn.lock,
pnpm-lock.yaml) that cannot be hand-edited:
for N in <pr numbers, space separated>; do
echo "=== PR $N ==="
if gh pr diff "$N" 2>/dev/null | git apply --3way; then
echo "PR $N applied"
else
echo "PR $N did NOT apply cleanly — handle manually (see Step 3)"
fi
doneApply them one at a time in the same loop so each result is visible. A PR that
applies cleanly prints Applied patch ... cleanly (or nothing on success with
plain git apply); a failure is reported explicitly.
git apply can fail when the local file has already diverged from the PR's
base (for example, an earlier PR in this same run already changed an adjacent
line in a way the 3-way merge could not reconcile, or the PR's lockfile diff
references hashes that no longer match). For each such PR:
gh pr diff <N>uvicorn>=0.48.0 → uvicorn>=0.49.0 (Python) or
"react": "^18.3.0" → "react": "^18.4.0" (JS). Open the target file
named in the diff header (+++ b/<path>) and apply the same edit by hand
with the Edit tool.pyproject.toml next to uv.lock → uv lockpackage.json next to package-lock.json →
npm install --package-lock-only --prefix <dir>package.json next to yarn.lock →
yarn install --cwd <dir>package.json next to pnpm-lock.yaml →
pnpm install --dir <dir> --lockfile-onlygit apply --3way stages successful merges, so plain git diff will look
empty. Use --cached to see the changes:
git status --short
git diff --cached --stat
git diff --cached -- '*requirements.txt' 'pyproject.toml' '**/package.json'Every old version constraint from a matched PR should now show as the new
version in the staged diff. Lockfile churn (uv.lock, package-lock.json,
yarn.lock, pnpm-lock.yaml) will also appear and is expected. Report any PR
whose change is missing.
Summarize what was carried over. Do not commit, push, or merge unless the
user asks — leave the changes staged in the working tree for their review.
Group by ecosystem so the user can copy Closes #N lines into the eventual PR
body:
Synced 5 app-dep Dependabot PRs into the working tree:
Python (pip):
#271 fastapi >=0.136.3 → >=0.137.1 oss-crs-infra/builder-sidecar/requirements.txt
#270 fastapi >=0.136.3 → >=0.137.1 oss-crs-infra/runner-sidecar/requirements.txt
#266 python-multipart >=0.0.30 → >=0.0.32 oss-crs-infra/runner-sidecar/requirements.txt
#265 python-multipart >=0.0.30 → >=0.0.32 oss-crs-infra/builder-sidecar/requirements.txt
JS (npm_and_yarn):
#284 @docusaurus/core ^3.7.0 → ^3.8.0 site/package.json (+ package-lock.json)
Files changed: 2 requirements.txt, 1 package.json, 1 package-lock.json
Not applied: (none)Mention any PRs that needed the Step 3 fallback, and any that still did not apply so the user can resolve them manually.
© ossf, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/sync-dependabot-app-deps of ossf/oss-crs.
Open the folder on GitHubat commit 4037c51
Sync Dependabot App Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sync Dependabot App Deps this skillossf/oss-crs | 165 | — | ~1.7k | Automated safety check: Notes | MIT | |
| Uv WorkflowAedelon/claude-code-blueprint | 120 | — | ~1.2k | Automated safety check: Notes | Custom licence | |
| Flowfile Build and Environment SetupEdwardvaneechoud/Flowfile | 385 | — | ~7.3k | Automated safety check: Notes | MIT | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT | |
| Deps Bumplkmeta/txtify | 135 | — | ~585 | Automated safety check: Pass | Apache-2.0 | |
| Dependency Updategocronx-team/gocron | 801 | — | ~891 | Automated safety check: Pass | MIT |
Aedelon/claude-code-blueprint
Master uv package manager for Python: project setup, dependency management, virtual environments, lockfiles, CI/CD integration, Docker builds, and migration from pip/poetry.
Edwardvaneechoud/Flowfile
Recreates every Flowfile development and build environment from scratch, with exact version pins and an explanation of what each Makefile target really does.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
lkmeta/txtify
Safely update Txtify dependencies or resolve Dependabot alerts.
gocronx-team/gocron
Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests.
pierrecomputer/pierre
Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.
ossf/oss-crs
After a Dependabot bump of oss-crs-infra/dependabot-pins.Dockerfile, resolve the human-readable version tag for each updated digest, fix the inline comment, and sync the digest to…
Categories
Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…. Sync Dependabot App Deps is an agent skill from ossf/oss-crs.yaml) without merging the PRs.
Sync Dependabot App Deps fits situations like: tasks that involve Dependency management.
Run `npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a claude-code`. Or copy the skill folder (.claude/skills/sync-dependabot-app-deps in ossf/oss-crs) into .claude/skills/sync-dependabot-app-deps in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a codex`. Or copy the skill folder (.claude/skills/sync-dependabot-app-deps in ossf/oss-crs) into .agents/skills/sync-dependabot-app-deps in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sync-dependabot-app-deps, .gemini/skills/sync-dependabot-app-deps, .github/skills/sync-dependabot-app-deps and .opencode/skills/sync-dependabot-app-deps in your project.
Going by SKILL.md and its folder, Sync Dependabot App Deps needs the command-line tools its instructions call (git, gh, python, uv, npm and yarn). Our summary lists: Python 3; Node.js; Docker. Its frontmatter pre-approves these tools: Read, Bash, Edit.
SKILL.md contains no URLs. Its commands use git, gh, uv and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Sync Dependabot App Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sync Dependabot App Deps: Uv Workflow (Aedelon/claude-code-blueprint, 120 stars), Flowfile Build and Environment Setup (Edwardvaneechoud/Flowfile, 385 stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and Deps Bump (lkmeta/txtify, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ossf (a GitHub organization) maintains it in ossf/oss-crs, which has 165 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 9, 2026.
Source: ossf/oss-crs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.