Agent skill

Sync Dependabot App Deps

by ossf in ossf/oss-crs

Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…

MITAuto-check: notesDevelopment

Install Sync Dependabot App Deps

skills CLI
$ npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ossf/oss-crs sync-dependabot-app-deps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ossf/oss-crs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sync-dependabot-app-deps .claude/skills/sync-dependabot-app-deps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sync-dependabot-app-deps
GitHub stars
165
Token cost
~1.7k tokens
SKILL.md length
721 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…

  • Works in 6 steps: Start from an up-to-date main on a fresh… → Enumerate the open Python and JS… → Apply each PR's diff to the local… → …
  • Tasks that involve Dependency management
  • SKILL.md covers Step 0 — Start from an…, Step 1 — Enumerate the open…, Step 2 — Apply each PR's diff… and Step 3 — Fallback for any PR…, plus 2 more sections
  • Calls git, gh and python

What it does

Sync Dependabot App Deps is an agent skill from ossf/oss-crs. Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt, pyproject.toml, uv.lock, package.json, package-lock.json/yarn.lock/pnpm-lock.yaml) without merging the PRs.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management. It works with npm, Python, pnpm and Docker. The repository describes itself as: Cyber Reasoning Systems for Bug-Finding and Patching in Open Source Software. The licence is MIT.

When your agent uses it

  • Tasks that involve Dependency management

Example prompts

  • “/sync-dependabot-app-deps”

Requirements

  • Python 3
  • Node.js
  • Docker
  • Pre-approved tools (allowed-tools): Read, Bash, Edit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Start from an up-to-date main on a fresh branch
  2. Enumerate the open Python and JS Dependabot PRs
  3. Apply each PR's diff to the local working tree
  4. Fallback for any PR that does not apply cleanly
  5. Verify the result
  6. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 4037c51. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • python
    • uv
    • npm
    • yarn
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, gh, uv, npm, yarn and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sync Dependabot App Deps loads about 1.7k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 721 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Edit

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ossf/oss-crs at commit 4037c51, republished under its MIT licence (© ossf). 721 words, ~1,683 tokens.

Download SKILL.mdSave it as .claude/skills/sync-dependabot-app-deps/SKILL.md (or your agent's skills folder).
name
sync-dependabot-app-deps
description
Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt, pyproject.toml, uv.lock, package.json, package-lock.json/yarn.lock/pnpm-lock.yaml) without merging the PRs.
allowed-tools
Read, Bash, Edit

Sync Dependabot App-Dependency Updates

Dependabot opens one PR per application-code dependency bump across several directories (Python: /, /oss-crs-infra/builder-sidecar, /oss-crs-infra/runner-sidecar, /oss-crs-infra/lifecycle, /oss-crs-infra/litellm-key-gen; JS: /site and any other npm package — see .github/dependabot.yml). This skill collects all the open Python and JS PRs and applies their changes directly to the local working tree, so the bumps land in one local change set instead of N separate merges.

The reliable signal for "this PR is an app-dep bump" is the branch name prefix:

  • Python (pip): dependabot/pip/ — used for plain requirements.txt directories
  • Python (uv): dependabot/uv/ — used for the root project that ships a uv.lock
  • JS (npm / yarn / pnpm): dependabot/npm_and_yarn/

Both Python prefixes must be matched. Dependabot picks uv/ over pip/ for any directory where it detects a uv.lock, regardless of how the directory is declared in .github/dependabot.yml. Missing dependabot/uv/ silently drops the root project's PRs.

GitHub Actions (dependabot/github_actions/) and Docker (dependabot/docker/) PRs are excluded — leave them alone (Docker has its own skill, sync-dependabot-pins).

Step 0 — Start from an up-to-date main on a fresh branch

Make sure the working tree is clean first (git status --short); if there are uncommitted changes, stop and ask the user how to proceed rather than pulling over them. Then update main and cut a dated working branch so the carried-over bumps land in one reviewable branch:

bash
git checkout main
git pull
git checkout -b "chore/app-deps-dependabot-$(date +%Y-%m-%d)"

If the branch already exists (the skill was run earlier today), switch to it instead: git checkout "chore/app-deps-dependabot-$(date +%Y-%m-%d)".

Step 1 — Enumerate the open Python and JS Dependabot PRs

bash
gh pr list --author "app/dependabot" --state open --limit 100 \
  --json number,title,headRefName \
  --jq '.[] | select(.headRefName | startswith("dependabot/pip/") or startswith("dependabot/uv/") or startswith("dependabot/npm_and_yarn/")) | "\(.number)\t\(.headRefName)\t\(.title)"'

If this prints nothing, there are no open Python or JS Dependabot PRs — stop and tell the user there is nothing to sync.

Otherwise, list the matched PR numbers to the user before applying so they know what is about to change. It is helpful to group them by ecosystem (pip vs npm_and_yarn) in the report.

Step 2 — Apply each PR's diff to the local working tree

For each matched PR number N, apply its diff with a 3-way merge. --3way lets two PRs that touch the same file (e.g. one bumps uvicorn, another bumps python-multipart in the same requirements.txt; or two npm bumps that both touch package-lock.json) both land cleanly, and it correctly carries generated lockfile changes (uv.lock, package-lock.json, yarn.lock, pnpm-lock.yaml) that cannot be hand-edited:

bash
for N in <pr numbers, space separated>; do
  echo "=== PR $N ==="
  if gh pr diff "$N" 2>/dev/null | git apply --3way; then
    echo "PR $N applied"
  else
    echo "PR $N did NOT apply cleanly — handle manually (see Step 3)"
  fi
done

Apply them one at a time in the same loop so each result is visible. A PR that applies cleanly prints Applied patch ... cleanly (or nothing on success with plain git apply); a failure is reported explicitly.

Show full SKILL.md (319 more words)Show less

Step 3 — Fallback for any PR that does not apply cleanly

git apply can fail when the local file has already diverged from the PR's base (for example, an earlier PR in this same run already changed an adjacent line in a way the 3-way merge could not reconcile, or the PR's lockfile diff references hashes that no longer match). For each such PR:

  1. Read the diff to see exactly what changed:
    bash
    gh pr diff <N>
  2. The change is almost always a single dependency constraint, e.g. uvicorn>=0.48.0 → uvicorn>=0.49.0 (Python) or "react": "^18.3.0" → "react": "^18.4.0" (JS). Open the target file named in the diff header (+++ b/<path>) and apply the same edit by hand with the Edit tool.
  3. After editing the manifest, regenerate the matching lockfile rather than editing it by hand. Pick the tool that matches the lockfile already present in that directory — do not introduce a different package manager:
    • Python pyproject.toml next to uv.lock → uv lock
    • npm package.json next to package-lock.json → npm install --package-lock-only --prefix <dir>
    • yarn package.json next to yarn.lock → yarn install --cwd <dir>
    • pnpm package.json next to pnpm-lock.yaml → pnpm install --dir <dir> --lockfile-only

Step 4 — Verify the result

git apply --3way stages successful merges, so plain git diff will look empty. Use --cached to see the changes:

bash
git status --short
git diff --cached --stat
git diff --cached -- '*requirements.txt' 'pyproject.toml' '**/package.json'

Every old version constraint from a matched PR should now show as the new version in the staged diff. Lockfile churn (uv.lock, package-lock.json, yarn.lock, pnpm-lock.yaml) will also appear and is expected. Report any PR whose change is missing.

Step 5 — Report

Summarize what was carried over. Do not commit, push, or merge unless the user asks — leave the changes staged in the working tree for their review. Group by ecosystem so the user can copy Closes #N lines into the eventual PR body:

Synced 5 app-dep Dependabot PRs into the working tree:

Python (pip):
  #271  fastapi           >=0.136.3 → >=0.137.1   oss-crs-infra/builder-sidecar/requirements.txt
  #270  fastapi           >=0.136.3 → >=0.137.1   oss-crs-infra/runner-sidecar/requirements.txt
  #266  python-multipart  >=0.0.30  → >=0.0.32    oss-crs-infra/runner-sidecar/requirements.txt
  #265  python-multipart  >=0.0.30  → >=0.0.32    oss-crs-infra/builder-sidecar/requirements.txt

JS (npm_and_yarn):
  #284  @docusaurus/core  ^3.7.0 → ^3.8.0         site/package.json (+ package-lock.json)

Files changed: 2 requirements.txt, 1 package.json, 1 package-lock.json
Not applied: (none)

Mention any PRs that needed the Step 3 fallback, and any that still did not apply so the user can resolve them manually.

© ossf, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/sync-dependabot-app-deps of ossf/oss-crs.

Open the folder on GitHubat commit 4037c51

Compare with similar skills

Sync Dependabot App Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sync Dependabot App Deps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sync Dependabot App Deps this skillossf/oss-crs165—~1.7kAutomated safety check: NotesMIT
Uv WorkflowAedelon/claude-code-blueprint120—~1.2kAutomated safety check: NotesCustom licence
Flowfile Build and Environment SetupEdwardvaneechoud/Flowfile385—~7.3kAutomated safety check: NotesMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Deps Bumplkmeta/txtify135—~585Automated safety check: PassApache-2.0
Dependency Updategocronx-team/gocron801—~891Automated safety check: PassMIT

Similar skills

  • Uv Workflow

    Aedelon/claude-code-blueprint

    Master uv package manager for Python: project setup, dependency management, virtual environments, lockfiles, CI/CD integration, Docker builds, and migration from pip/poetry.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • Flowfile Build and Environment Setup

    Edwardvaneechoud/Flowfile

    Recreates every Flowfile development and build environment from scratch, with exact version pins and an explanation of what each Makefile target really does.

    385 GitHub stars~7.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Deps Bump

    lkmeta/txtify

    Safely update Txtify dependencies or resolve Dependabot alerts.

    135 GitHub stars~585 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Dependency Update

    gocronx-team/gocron

    Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests.

    801 GitHub stars~891 tokensUpdated today
    DevelopmentAuto-check passed
  • Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.

    6.3k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed

More from ossf/oss-crs

  • After a Dependabot bump of oss-crs-infra/dependabot-pins.Dockerfile, resolve the human-readable version tag for each updated digest, fix the inline comment, and sync the digest to…

    165 GitHub stars~1.7k tokensUpdated today
    Auto-check: notes

Categories

Questions about Sync Dependabot App Deps

What does Sync Dependabot App Deps do?

Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…. Sync Dependabot App Deps is an agent skill from ossf/oss-crs.yaml) without merging the PRs.

When should I use Sync Dependabot App Deps?

Sync Dependabot App Deps fits situations like: tasks that involve Dependency management.

How do I install Sync Dependabot App Deps in Claude Code?

Run `npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a claude-code`. Or copy the skill folder (.claude/skills/sync-dependabot-app-deps in ossf/oss-crs) into .claude/skills/sync-dependabot-app-deps in your project. Claude Code loads it when a task matches its description.

How do I install Sync Dependabot App Deps in Codex?

Run `npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a codex`. Or copy the skill folder (.claude/skills/sync-dependabot-app-deps in ossf/oss-crs) into .agents/skills/sync-dependabot-app-deps in your project. Codex loads it when a task matches its description.

Can I use Sync Dependabot App Deps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ossf/oss-crs --skill sync-dependabot-app-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sync-dependabot-app-deps, .gemini/skills/sync-dependabot-app-deps, .github/skills/sync-dependabot-app-deps and .opencode/skills/sync-dependabot-app-deps in your project.

What does Sync Dependabot App Deps need to run?

Going by SKILL.md and its folder, Sync Dependabot App Deps needs the command-line tools its instructions call (git, gh, python, uv, npm and yarn). Our summary lists: Python 3; Node.js; Docker. Its frontmatter pre-approves these tools: Read, Bash, Edit.

Does Sync Dependabot App Deps access the network?

SKILL.md contains no URLs. Its commands use git, gh, uv and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sync Dependabot App Deps safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Sync Dependabot App Deps use?

Sync Dependabot App Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sync Dependabot App Deps use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sync Dependabot App Deps?

Skills that share tags, products or a category with Sync Dependabot App Deps: Uv Workflow (Aedelon/claude-code-blueprint, 120 stars), Flowfile Build and Environment Setup (Edwardvaneechoud/Flowfile, 385 stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and Deps Bump (lkmeta/txtify, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sync Dependabot App Deps?

ossf (a GitHub organization) maintains it in ossf/oss-crs, which has 165 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 9, 2026.

Source: ossf/oss-crs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.