Agent skill

Sync Dependabot Pins

by ossf in ossf/oss-crs

After a Dependabot bump of oss-crs-infra/dependabot-pins.Dockerfile, resolve the human-readable version tag for each updated digest, fix the inline comment, and sync the digest to…

MITAuto-check: notesDevelopment

Install Sync Dependabot Pins

skills CLI
$ npx skills add ossf/oss-crs --skill sync-dependabot-pins -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ossf/oss-crs sync-dependabot-pins --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ossf/oss-crs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sync-dependabot-pins .claude/skills/sync-dependabot-pins && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sync-dependabot-pins
GitHub stars
165
Token cost
~1.7k tokens
SKILL.md length
507 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

After a Dependabot bump of oss-crs-infra/dependabot-pins.Dockerfile, resolve the human-readable version tag for each updated digest, fix the inline comment, and sync the digest to…

  • Works in 7 steps: Confirm the latest commit touched… → Read the current Dockerfile → Identify what changed → …
  • Tasks that involve Dependency management
  • SKILL.md covers Step 1 — Confirm the latest…, Step 2 — Read the current…, Step 3 — Identify what changed and Step 4 — Resolve the…, plus 4 more sections
  • Calls curl, python3 and docker; reaches registry.hub.docker.com and ghcr.io

What it does

Sync Dependabot Pins is an agent skill from ossf/oss-crs. After a Dependabot bump of oss-crs-infra/dependabot-pins.Dockerfile, resolve the human-readable version tag for each updated digest, fix the inline comment, and sync the digest to osscrs/src/constants.py.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management, Containers and Technical documentation. It works with Docker. The repository describes itself as: Cyber Reasoning Systems for Bug-Finding and Patching in Open Source Software. The licence is MIT.

When your agent uses it

  • Tasks that involve Dependency management
  • Tasks that involve Containers
  • Tasks that involve Technical documentation

Example prompts

  • “/sync-dependabot-pins”

Requirements

  • Python 3
  • Docker
  • Pre-approved tools (allowed-tools): Read, Bash, Edit

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Confirm the latest commit touched dependabot-pins.Dockerfile
  2. Read the current Dockerfile
  3. Identify what changed
  4. Resolve the human-readable version for each changed digest
  5. Update the inline comment in dependabot-pins.Dockerfile
  6. Sync digests to oss_crs/src/constants.py
  7. Verify the sync

What it can do on your machine

Read from SKILL.md and the folder at commit 02b2b0d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3
    • docker
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.hub.docker.com
    • ghcr.io
    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sync Dependabot Pins loads about 1.7k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 507 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Edit

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ossf/oss-crs at commit 02b2b0d, republished under its MIT licence (© ossf). 507 words, ~1,731 tokens.

Download SKILL.mdSave it as .claude/skills/sync-dependabot-pins/SKILL.md (or your agent's skills folder).
name
sync-dependabot-pins
description
After a Dependabot bump of oss-crs-infra/dependabot-pins.Dockerfile, resolve the human-readable version tag for each updated digest, fix the inline comment, and sync the digest to oss_crs/src/constants.py.
allowed-tools
Read, Bash, Edit

Sync Dependabot Pins

Dependabot updates image digests in oss-crs-infra/dependabot-pins.Dockerfile but leaves version comments stale or copies the old one. This skill resolves the correct human-readable version for each changed digest, patches the Dockerfile comment, and syncs the digest to oss_crs/src/constants.py.

Step 1 — Confirm the latest commit touched dependabot-pins.Dockerfile

bash
git log --oneline -1 -- oss-crs-infra/dependabot-pins.Dockerfile

If no output, the latest commit did not touch this file. Stop here and tell the user there is nothing to sync.

Step 2 — Read the current Dockerfile

Read oss-crs-infra/dependabot-pins.Dockerfile and extract every FROM line. Each has the form:

FROM <image>@sha256:<digest>  # <version-comment>

Note the image name, full digest, and existing comment for each line.

Step 3 — Identify what changed

bash
git diff HEAD~1 HEAD -- oss-crs-infra/dependabot-pins.Dockerfile

Only process the FROM lines whose digest actually changed. Leave unchanged lines alone.

Step 4 — Resolve the human-readable version for each changed digest

For each changed image, use docker buildx imagetools inspect to scan release tags until the digest matches. This avoids pulling the image and works for multi-platform indexes.

For ghcr.io/berriai/litellm-database

The image uses semver tags (v1.86.1, v1.87.0, etc.) that match the BerriAI/litellm GitHub release tags. Fetch recent releases and resolve each one's digest:

bash
TARGET_DIGEST="sha256:<new-digest>"

# Get recent release tags from GitHub
TAGS=$(curl -s "https://api.github.com/repos/BerriAI/litellm/releases?per_page=20" \
  | python3 -c "import json,sys; [print(r['tag_name']) for r in json.load(sys.stdin) if not r.get('prerelease')]")

# Resolve each tag to its OCI index digest and look for a match
for tag in $TAGS; do
  DIGEST=$(docker buildx imagetools inspect "ghcr.io/berriai/litellm-database:$tag" \
    --format '{{.Manifest.Digest}}' 2>/dev/null)
  echo "$tag -> $DIGEST"
  if [ "$DIGEST" = "$TARGET_DIGEST" ]; then
    echo "MATCH FOUND: $tag"
    break
  fi
done

If the matching tag is not in the first 20 releases, broaden the search with per_page=50 or check older pages.

For postgres (Docker Hub)
bash
TARGET_DIGEST="sha256:<new-digest>"

# Fetch recent postgres tags and resolve each
curl -s "https://registry.hub.docker.com/v2/repositories/library/postgres/tags?page_size=50&ordering=last_updated" \
  | python3 -c "
import json,sys
data=json.load(sys.stdin)
for t in data.get('results',[]):
    # Skip non-numeric tags (alpha, beta, etc.)
    name=t['name']
    if name[0].isdigit():
        print(name)
" | while read tag; do
  DIGEST=$(docker buildx imagetools inspect "postgres:$tag" \
    --format '{{.Manifest.Digest}}' 2>/dev/null)
  if [ "$DIGEST" = "$TARGET_DIGEST" ]; then
    echo "MATCH FOUND: $tag"
    break
  fi
done

If docker buildx imagetools inspect returns empty digests (Docker Hub rate-limits anonymous manifest inspects, often hitting newer tags like the 18.x series while older tags still resolve), skip buildx entirely and match against the digests already embedded in the Docker Hub tags API response. Each tag entry carries a top-level digest (the multi-arch OCI index digest, which is what the FROM ...@sha256: pin uses) plus per-images digests:

bash
TARGET_DIGEST="sha256:<new-digest>"

for page in 1 2 3; do
curl -s "https://registry.hub.docker.com/v2/repositories/library/postgres/tags?page_size=100&page=$page&ordering=last_updated" \
  | python3 -c "
import json,sys
target='$TARGET_DIGEST'
data=json.load(sys.stdin)
for t in data.get('results',[]):
    if t.get('digest','')==target:
        print('MATCH (index digest):', t['name'])
    for img in t.get('images',[]):
        if img.get('digest','')==target:
            print('MATCH (image digest):', t['name'], img.get('os'), img.get('architecture'))
"
done

This usually returns several aliases for one digest (e.g. 18.4, 18, trixie, latest). Pick the most specific numeric version tag (18.4) for the comment. Note that a digest bump does not always mean a version bump — a rebuild of the same version with refreshed base packages keeps the same numeric tag, so the existing comment may already be correct.

Show full SKILL.md (178 more words)Show less
Fallback — Inspect the Dependabot commit message

The commit message from git log -1 -- oss-crs-infra/dependabot-pins.Dockerfile sometimes contains release note links. You can also check GHCR tags directly:

bash
TOKEN=$(curl -s "https://ghcr.io/token?service=ghcr.io&scope=repository:berriai/litellm-database:pull" \
  | python3 -c 'import json,sys; print(json.load(sys.stdin)["token"])')
curl -s -H "Authorization: Bearer $TOKEN" "https://ghcr.io/v2/berriai/litellm-database/tags/list" \
  | python3 -c "import json,sys; print('\n'.join(data.get('tags',[]) for data in [json.load(sys.stdin)]))"

If no strategy resolves the version, leave the comment as # <unknown> and note it in your response so the user can fill it in manually.

Step 5 — Update the inline comment in dependabot-pins.Dockerfile

For each changed FROM line, replace the old comment with the resolved version:

FROM <image>@sha256:<new-digest>  # <resolved-version>

Use the Edit tool to make this change.

Step 6 — Sync digests to oss_crs/src/constants.py

Read oss_crs/src/constants.py. It contains constants of the form:

python
LITELLM_IMAGE = "ghcr.io/berriai/litellm-database@sha256:<digest>"  # <version>
POSTGRES_IMAGE = "postgres@sha256:<digest>"  # <version>

The mapping from Dockerfile FROM image to Python constant is:

Dockerfile image prefixPython constant
ghcr.io/berriai/litellm-databaseLITELLM_IMAGE
postgresPOSTGRES_IMAGE

For each changed image, update both the digest and the inline comment in constants.py to match what is now in dependabot-pins.Dockerfile. Use the Edit tool.

Step 7 — Verify the sync

After editing, confirm the digests and comments match between the two files:

bash
grep -E 'sha256:|# v|# [0-9]' oss-crs-infra/dependabot-pins.Dockerfile oss_crs/src/constants.py

All digests that appear in dependabot-pins.Dockerfile must appear verbatim in constants.py. Report any mismatch.

Example Output

After a successful sync, report something like:

Updated: ghcr.io/berriai/litellm-database
  Old digest: 069da88...  # v1.84.1
  New digest: 49f8919...  # v1.85.0
  Updated in: oss-crs-infra/dependabot-pins.Dockerfile, oss_crs/src/constants.py

© ossf, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/sync-dependabot-pins of ossf/oss-crs.

Open the folder on GitHubat commit 02b2b0d

Compare with similar skills

Sync Dependabot Pins next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sync Dependabot Pins compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sync Dependabot Pins this skillossf/oss-crs165—~1.7kAutomated safety check: NotesMIT
Megatron-LM Container and Dependency SetupNVIDIA/Megatron-LM18k—~2.6kAutomated safety check: PassApache-2.0
Flowfile Build and Environment SetupEdwardvaneechoud/Flowfile375—~7.3kAutomated safety check: NotesMIT
AI ServerOpentrons/opentrons523—~2.5kAutomated safety check: NotesApache-2.0
Setup Mulmoclaudereceptron/mulmoclaude368—~1kAutomated safety check: NotesMIT
Dockerfile And Readme Templatingdotnet/dotnet-docker4.9k—~563Automated safety check: PassMIT

Similar skills

  • Official

    Walks an agent through working inside the Megatron-LM CI container and changing dependencies with uv, so lock files resolve the same locally and in CI.

    18k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Flowfile Build and Environment Setup

    Edwardvaneechoud/Flowfile

    Recreates every Flowfile development and build environment from scratch, with exact version pins and an explanation of what each Makefile target really does.

    375 GitHub stars~7.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • AI Server

    Opentrons/opentrons

    Conventions for the opentrons-ai-server FastAPI service — project structure, uv dependency management, settings, testing, Docker, and deployment.

    523 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Setup Mulmoclaude

    receptron/mulmoclaude

    Interactively guide MulmoClaude setup following README instructions.

    368 GitHub stars~1k tokensUpdated today
    Media & CreativeAuto-check: notes
  • Official

    Modify Cottle templates that generate Dockerfiles and READMEs in dotnet/dotnet-docker.

    4.9k GitHub stars~563 tokensUpdated today
    DevOps & CloudAuto-check passed
  • 1panel App Builder

    arch3rPro/1Panel-Appstore

    A skill your agent uses when packaging Docker deployments as 1Panel local app store apps, including GitHub projects, docker-compose.yml files, docker run commands, app metadata, version directories…

    213 GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed

More from ossf/oss-crs

  • Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…

    165 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check: notes

Works with

Questions about Sync Dependabot Pins

What does Sync Dependabot Pins do?

After a Dependabot bump of oss-crs-infra/dependabot-pins.Dockerfile, resolve the human-readable version tag for each updated digest, fix the inline comment, and sync the digest to…. Sync Dependabot Pins is an agent skill from ossf/oss-crs.py.

When should I use Sync Dependabot Pins?

Sync Dependabot Pins fits situations like: tasks that involve Dependency management; tasks that involve Containers; tasks that involve Technical documentation.

How do I install Sync Dependabot Pins in Claude Code?

Run `npx skills add ossf/oss-crs --skill sync-dependabot-pins -a claude-code`. Or copy the skill folder (.claude/skills/sync-dependabot-pins in ossf/oss-crs) into .claude/skills/sync-dependabot-pins in your project. Claude Code loads it when a task matches its description.

How do I install Sync Dependabot Pins in Codex?

Run `npx skills add ossf/oss-crs --skill sync-dependabot-pins -a codex`. Or copy the skill folder (.claude/skills/sync-dependabot-pins in ossf/oss-crs) into .agents/skills/sync-dependabot-pins in your project. Codex loads it when a task matches its description.

Can I use Sync Dependabot Pins in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ossf/oss-crs --skill sync-dependabot-pins -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sync-dependabot-pins, .gemini/skills/sync-dependabot-pins, .github/skills/sync-dependabot-pins and .opencode/skills/sync-dependabot-pins in your project.

What does Sync Dependabot Pins need to run?

Going by SKILL.md and its folder, Sync Dependabot Pins needs the command-line tools its instructions call (curl, python3, docker and git). Our summary lists: Python 3; Docker. Its frontmatter pre-approves these tools: Read, Bash, Edit.

Does Sync Dependabot Pins access the network?

SKILL.md names 3 domains. In commands or code: registry.hub.docker.com, ghcr.io and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Sync Dependabot Pins safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Sync Dependabot Pins use?

Sync Dependabot Pins is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sync Dependabot Pins use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sync Dependabot Pins?

Skills that share tags, products or a category with Sync Dependabot Pins: Megatron-LM Container and Dependency Setup (NVIDIA/Megatron-LM, 18k stars), Flowfile Build and Environment Setup (Edwardvaneechoud/Flowfile, 375 stars), AI Server (Opentrons/opentrons, 523 stars) and Setup Mulmoclaude (receptron/mulmoclaude, 368 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sync Dependabot Pins?

ossf (a GitHub organization) maintains it in ossf/oss-crs, which has 165 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 6, 2026.

Source: ossf/oss-crs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.