Dependabot Alerts Update
livesession/xyd
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.
$ npx skills add owid/etl --skill fix-dependabot -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install owid/etl fix-dependabot --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/owid/etl.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/fix-dependabot .claude/skills/fix-dependabot && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fix-dependabot" agent skill from https://github.com/owid/etl/tree/master/.claude/skills/fix-dependabot into .claude/skills/fix-dependabot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-dependabot", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/owid/etl/tree/master/.claude/skills/fix-dependabotType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add owid/etl --skill fix-dependabot -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install owid/etl fix-dependabot --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/owid/etl.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/fix-dependabot .agents/skills/fix-dependabot && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fix-dependabot" agent skill from https://github.com/owid/etl/tree/master/.claude/skills/fix-dependabot into .agents/skills/fix-dependabot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-dependabot", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add owid/etl --skill fix-dependabot -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install owid/etl fix-dependabot --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/owid/etl.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/fix-dependabot .cursor/skills/fix-dependabot && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fix-dependabot" agent skill from https://github.com/owid/etl/tree/master/.claude/skills/fix-dependabot into .cursor/skills/fix-dependabot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-dependabot", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/owid/etl.git --path .claude/skills/fix-dependabot--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add owid/etl --skill fix-dependabot -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install owid/etl fix-dependabot --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/owid/etl.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/fix-dependabot .gemini/skills/fix-dependabot && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fix-dependabot" agent skill from https://github.com/owid/etl/tree/master/.claude/skills/fix-dependabot into .gemini/skills/fix-dependabot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-dependabot", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install owid/etl fix-dependabotInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add owid/etl --skill fix-dependabot -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/owid/etl.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/fix-dependabot .github/skills/fix-dependabot && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fix-dependabot" agent skill from https://github.com/owid/etl/tree/master/.claude/skills/fix-dependabot into .github/skills/fix-dependabot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-dependabot", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add owid/etl --skill fix-dependabot -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install owid/etl fix-dependabot --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/owid/etl.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/fix-dependabot .opencode/skills/fix-dependabot && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fix-dependabot" agent skill from https://github.com/owid/etl/tree/master/.claude/skills/fix-dependabot into .opencode/skills/fix-dependabot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-dependabot", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fix-dependabotResolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.
Fix Dependabot is an agent skill from owid/etl. Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies. Use when the user mentions "dependabot", "security alerts", "vulnerability", "CVE", "security fixes", "dependabot alerts", or wants to fix vulnerable packages. Also trigger when the user pastes a GitHub Dependabot URL or asks about outdated/insecure dependencies.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management and Vulnerability scanning. It works with GitHub and npm. The repository describes itself as: A compute graph for loading and transforming OWID's data. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d5ba5a6. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmuvghrgmakeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
pypi.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fix Dependabot loads about 2.9k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 1,356 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from owid/etl at commit d5ba5a6, republished under its MIT licence (© owid). 1,356 words, ~2,895 tokens.
.claude/skills/fix-dependabot/SKILL.md (or your agent's skills folder).Resolve open Dependabot security alerts by upgrading vulnerable dependencies across the ETL monorepo — including pip packages (pyproject.toml + uv.lock), lib/ subdirectories, and npm packages in vscode_extensions/.
Goal: leave zero open Dependabot PRs. Security alerts are the priority, but Dependabot also opens routine version-update PRs that have no associated alert (e.g. esbuild minor bumps, or js-yaml bumps in extensions GitHub didn't flag). Don't stop at the alerts — also clear these (Step 4c) so the PR list is empty afterward. The default is to fold every open Dependabot PR's bump into the single batch PR and close the originals; if the user only wants the security alerts, scope to those instead.
gh api repos/owid/etl/dependabot/alerts \
--jq '.[] | select(.state == "open") | {
number, state,
package: .dependency.package.name,
ecosystem: .dependency.package.ecosystem,
severity: .security_advisory.severity,
summary: .security_advisory.summary,
patched: .security_advisory.vulnerabilities[0].first_patched_version.identifier,
manifest: .dependency.manifest_path
}'Present a summary table grouped by severity (critical > high > medium > low) with counts, then the detailed list showing package, ecosystem, severity, and summary.
Ask the user which severities to fix (e.g. "critical and high only" or "all"). If the user already specified a filter in their request, proceed with that.
Always list open Dependabot PRs, not just open alerts. Dependabot PRs can remain open after the default branch already contains the requested dependency version (especially old/conflicted PRs where automatic rebases have been disabled).
gh pr list --repo owid/etl --author app/dependabot --state open \
--json number,title,headRefName,mergeStateStatus,files --limit 100 \
--jq '.[] | {number,title,mergeStateStatus,files:[.files[].path]}'For each open PR:
origin/master or master), not just your working branch. Check whether the dependency is already at the requested version or newer.uv.lock files, inspect the relevant package entry in the affected lockfile.package-lock.json and check all installed versions of the package in that extension.gh pr close <number> --repo owid/etl --comment \
"Closing as obsolete: the current default branch already has this dependency at the requested version or newer, so this stale Dependabot PR is no longer relevant."Map each open PR to an alert (or not). Cross-reference this PR list against the alert list from Step 1. A PR whose package/manifest matches an open alert is a security PR — handled by Steps 2–4. A PR with no matching open alert is a routine version-update PR — handled by Step 4c. Both kinds should be gone by the end.
For each alert to fix, determine:
pip or npmpyproject.toml (or a lib/*/pyproject.toml), or is it only in the lockfile as a transitive dependency?pyproject.toml or package.json owns this dependency?For pip packages, check all pyproject.toml files:
grep -rn '<package-name>' pyproject.toml lib/*/pyproject.tomlFor npm packages, check the manifest path from the alert (usually under vscode_extensions/).
If the package appears in a pyproject.toml dependencies or optional dependency group:
"package>=old_version" → "package>=patched_version"uv lock --upgrade-package <package> to update the lockfileIf the package is only in uv.lock (not a direct dependency):
uv tree --invert --package <vulnerable-package> --depth 1python3 -c "
import json, urllib.request
r = urllib.request.urlopen('https://pypi.org/pypi/<parent>/json')
d = json.loads(r.read())
deps = d['info'].get('requires_dist') or []
matches = [dep for dep in deps if '<vulnerable-pkg>' in dep.lower()]
print(matches)
"uv lock --upgrade-package <vulnerable-package>grep -rn 'import <parent>\|from <parent>' --include='*.py')pyproject.toml (this unblocks the transitive dep)[tool.uv] override (explain the tradeoff — overrides can cause runtime incompatibilities)When removing a package, check if it's imported anywhere in the codebase. If it is, replace its usage with an alternative approach. For example, when we removed moviepy, we replaced its ImageSequenceClip usage with a direct ffmpeg subprocess call.
Always search broadly:
rg 'import <package>|from <package>' --type pyFor each vulnerable npm package:
package.jsoncd <directory>
npm install # ensure node_modules exist
npm install <package>@^<patched-version>npm ls <package>Before adding a package to dependencies, check whether the extension actually imports it:
rg -l "from ['\"]<package>|require\(['\"]<package>" vscode_extensions/<ext>/srcsrc/ → it's a real runtime dependency; bump it in dependencies (npm install <package>@^<version>).dependencies (that creates a phantom runtime dep). Instead force the patched version via the existing overrides block in package.json, then npm install. This matches how Dependabot itself fixes those (lockfile-only).After the security alerts are handled, fold every remaining open Dependabot PR (the ones with no matching alert from Step 1b) into the same batch branch, then close them. These are routine bumps — usually npm devDeps in vscode_extensions/ (e.g. esbuild) or js-yaml in extensions GitHub didn't alert on.
For each remaining PR, apply its bump locally rather than merging the Dependabot branch (keeps everything in one PR with one CI run):
Bump <pkg> from <old> to <new> in /<path>).cd into the manifest's directory and apply it the same way as Step 4 (direct bump if imported in src/, overrides if a dev-tooling transitive — see above). For a pure devDependency like esbuild, bump it in devDependencies: npm install -D <pkg>@^<new>.npm ls <pkg>.After applying all of them, compile each touched extension so a bad bump fails locally, not in CI:
cd vscode_extensions/<ext> && npm run compile # or `npm run lint` if there's no compile scriptThen close each superseded Dependabot PR referencing the batch PR (do this in Step 6, after the batch PR exists):
gh pr close <number> --repo owid/etl --comment \
"Superseded by #<batch-PR>, which applies this bump as part of a single batched Dependabot sweep. Closing as obsolete."If a bump is risky or a major version jump with breaking changes, don't force it into the batch — leave that PR open and flag it for the user instead.
Run make check-all (lint + format + typecheck across the root and every lib/). The plain make check only covers the top-level codebase, so breaking changes from upgrades to packages used by lib/ (e.g. gdown's fuzzy= removal in lib/datautils/) would slip through.
If it fails, fix the issues (commonly: removed/renamed kwargs that type checkers flag) and re-run until it passes.
If you modified any lib/{catalog,datautils,repack}/pyproject.toml, also bump that file's version = "x.y.z" (patch bump). The publish-owid-packages.yml workflow republishes these packages to PyPI on master push and rejects the publish if the version already exists.
After bumping, re-run uv lock (top-level and inside each modified lib/<name>/) so the lockfiles pick up the new version.
Follow the standard ETL PR workflow:
.venv/bin/etl pr "Fix <severity> Dependabot vulnerabilities" dataStage and commit all changed files:
pyproject.toml and any lib/*/pyproject.tomluv.lock.py files (from removing unused deps)package.json / package-lock.json filesUse commit emoji 🐛🤖 (bug fix, AI-written).
After pushing, post @codex review as a PR comment.
Then close every open Dependabot PR this batch covers — both the security ones (Steps 2–4) and the version-update ones (Step 4c) — with a comment referencing this PR (see the close commands in Steps 1b and 4c). Finally, re-run the Step 1b PR list and confirm it's empty (modulo anything you deliberately left open and flagged for the user). If the title only covers security fixes but you also swept version updates, use a broader title like Fix Dependabot vulnerabilities and clear version-update PRs.
lib/ contains subdirectories (catalog, datautils, repack, walden) with their own pyproject.toml files — check these toouv.lock file may also be affected by [tool.uv] exclude-newer settings in pyproject.toml — if a patched version exists on PyPI but uv won't resolve it, check this settingauto_dismissed) — skip thoseuv lock --upgrade-package pkg1 --upgrade-package pkg2© owid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/fix-dependabot of owid/etl.
Open the folder on GitHubat commit d5ba5a6
Fix Dependabot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fix Dependabot this skillowid/etl | 159 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Dependabot Alerts Updatelivesession/xyd | 114 | — | ~2k | Automated safety check: Pass | MIT | |
| Fix Security PRunional/typescript-blackbook | 133 | — | ~1.4k | Automated safety check: Warn | MIT | |
| Stash Supply Chain Securitycipherstash/stack | 157 | — | ~5.2k | Automated safety check: Warn | MIT | |
| Dependency Update BotVarnan-Tech/opendirectory | 674 | — | ~3k | Automated safety check: Notes | MIT | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT |
livesession/xyd
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
unional/typescript-blackbook
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.
cipherstash/stack
Supply-chain security controls for the @cipherstash/stack monorepo.
Varnan-Tech/opendirectory
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
github/rust-gems
Keep dependencies up-to-date. An agent skill from github/rust-gems.
owid/etl
Find every OWID surface that references a chart, indicator, MDIM, or explorer — articles (links vs embeds), explorers, narrative charts, data insights, static viz, key-chart slots, MDIM views.
owid/etl
Add a scatter view (with GDP per capita on x) to existing OWID charts via the admin API, mirroring the admin UI's "Add scatter type" defaults, then retire the old standalone "X vs.
owid/etl
Add new survey question codes (e.g. An agent skill from owid/etl.
owid/etl
Build or refresh an OWID static visualization end to end — resolve what data it needs from an old static viz image, an indicator, or a grapher chart; check both the ETL catalog and the producer's…
owid/etl
Propose redirects from (soon-to-sunset) grapher charts to the matching views of published MDIMs.
owid/etl
Take (soon-to-sunset) OWID explorers to redirected MDIMs, end to end.
Categories
Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies. Fix Dependabot is an agent skill from owid/etl. Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.
Fix Dependabot fits situations like: the user mentions dependabot; security alerts; dependabot alerts; wants to fix vulnerable packages.
Run `npx skills add owid/etl --skill fix-dependabot -a claude-code`. Or copy the skill folder (.claude/skills/fix-dependabot in owid/etl) into .claude/skills/fix-dependabot in your project. Claude Code loads it when a task matches its description.
Run `npx skills add owid/etl --skill fix-dependabot -a codex`. Or copy the skill folder (.claude/skills/fix-dependabot in owid/etl) into .agents/skills/fix-dependabot in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add owid/etl --skill fix-dependabot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-dependabot, .gemini/skills/fix-dependabot, .github/skills/fix-dependabot and .opencode/skills/fix-dependabot in your project.
Going by SKILL.md and its folder, Fix Dependabot needs the command-line tools its instructions call (npm, uv, gh, rg and make). Our summary lists: Python 3; Node.js.
SKILL.md names 1 domain. In commands or code: pypi.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fix Dependabot is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fix Dependabot: Dependabot Alerts Update (livesession/xyd, 114 stars), Fix Security PR (unional/typescript-blackbook, 133 stars), Stash Supply Chain Security (cipherstash/stack, 157 stars) and Dependency Update Bot (Varnan-Tech/opendirectory, 674 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
owid (a GitHub organization) maintains it in owid/etl, which has 159 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 9, 2026.
Source: owid/etl on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.