Agent skill

Fix Dependabot

by owid in owid/etl

Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.

MITAuto-check passedDevelopment

Install Fix Dependabot

skills CLI
$ npx skills add owid/etl --skill fix-dependabot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install owid/etl fix-dependabot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/owid/etl.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/fix-dependabot .claude/skills/fix-dependabot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fix-dependabot
GitHub stars
159
Token cost
~2.9k tokens
SKILL.md length
1,356 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.

  • Works in 6 steps: Fetch and summarize alerts → Categorize each alert → Fix pip dependencies → …
  • The user mentions dependabot
  • SKILL.md covers Step 1: Fetch and summarize…, Step 1b: Audit existing…, Step 2: Categorize each alert and Step 3: Fix pip dependencies, plus 6 more sections
  • Calls npm, uv and gh; reaches pypi.org

What it does

Fix Dependabot is an agent skill from owid/etl. Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies. Use when the user mentions "dependabot", "security alerts", "vulnerability", "CVE", "security fixes", "dependabot alerts", or wants to fix vulnerable packages. Also trigger when the user pastes a GitHub Dependabot URL or asks about outdated/insecure dependencies.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management and Vulnerability scanning. It works with GitHub and npm. The repository describes itself as: A compute graph for loading and transforming OWID's data. The licence is MIT.

When your agent uses it

  • The user mentions dependabot
  • Security alerts
  • Dependabot alerts
  • Wants to fix vulnerable packages

Example prompts

  • “dependabot”
  • “security alerts”
  • “vulnerability”
  • “/fix-dependabot”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Fetch and summarize alerts
  2. Categorize each alert
  3. Fix pip dependencies
  4. Fix npm dependencies
  5. Verify changes
  6. Create PR

What it can do on your machine

Read from SKILL.md and the folder at commit d5ba5a6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • uv
    • gh
    • rg
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • pypi.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fix Dependabot loads about 2.9k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 1,356 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from owid/etl at commit d5ba5a6, republished under its MIT licence (© owid). 1,356 words, ~2,895 tokens.

Download SKILL.mdSave it as .claude/skills/fix-dependabot/SKILL.md (or your agent's skills folder).
name
fix-dependabot
description
Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies. Use when the user mentions "dependabot", "security alerts", "vulnerability", "CVE", "security fixes", "dependabot alerts", or wants to fix vulnerable packages. Also trigger when the user pastes a GitHub Dependabot URL or asks about outdated/insecure dependencies.
metadata.internal
true
metadata.owner
Marigold

Fix Dependabot Alerts

Resolve open Dependabot security alerts by upgrading vulnerable dependencies across the ETL monorepo — including pip packages (pyproject.toml + uv.lock), lib/ subdirectories, and npm packages in vscode_extensions/.

Goal: leave zero open Dependabot PRs. Security alerts are the priority, but Dependabot also opens routine version-update PRs that have no associated alert (e.g. esbuild minor bumps, or js-yaml bumps in extensions GitHub didn't flag). Don't stop at the alerts — also clear these (Step 4c) so the PR list is empty afterward. The default is to fold every open Dependabot PR's bump into the single batch PR and close the originals; if the user only wants the security alerts, scope to those instead.

Step 1: Fetch and summarize alerts

bash
gh api repos/owid/etl/dependabot/alerts \
  --jq '.[] | select(.state == "open") | {
    number, state,
    package: .dependency.package.name,
    ecosystem: .dependency.package.ecosystem,
    severity: .security_advisory.severity,
    summary: .security_advisory.summary,
    patched: .security_advisory.vulnerabilities[0].first_patched_version.identifier,
    manifest: .dependency.manifest_path
  }'

Present a summary table grouped by severity (critical > high > medium > low) with counts, then the detailed list showing package, ecosystem, severity, and summary.

Ask the user which severities to fix (e.g. "critical and high only" or "all"). If the user already specified a filter in their request, proceed with that.

Step 1b: Audit existing Dependabot PRs

Always list open Dependabot PRs, not just open alerts. Dependabot PRs can remain open after the default branch already contains the requested dependency version (especially old/conflicted PRs where automatic rebases have been disabled).

bash
gh pr list --repo owid/etl --author app/dependabot --state open \
  --json number,title,headRefName,mergeStateStatus,files --limit 100 \
  --jq '.[] | {number,title,mergeStateStatus,files:[.files[].path]}'

For each open PR:

  1. Identify the manifest/lockfile and target package/version from the title and changed files.
  2. Compare against the current default branch (origin/master or master), not just your working branch. Check whether the dependency is already at the requested version or newer.
    • For uv.lock files, inspect the relevant package entry in the affected lockfile.
    • For npm lockfiles, parse package-lock.json and check all installed versions of the package in that extension.
  3. If the PR is obsolete, close it with a clear comment, for example:
    bash
    gh pr close <number> --repo owid/etl --comment \
      "Closing as obsolete: the current default branch already has this dependency at the requested version or newer, so this stale Dependabot PR is no longer relevant."
  4. If you create a replacement PR that batches or supersedes Dependabot PRs, close the superseded PRs and reference the replacement PR in the close comment.
  5. Re-run the PR list and confirm there are no open irrelevant Dependabot PRs before reporting completion.

Map each open PR to an alert (or not). Cross-reference this PR list against the alert list from Step 1. A PR whose package/manifest matches an open alert is a security PR — handled by Steps 2–4. A PR with no matching open alert is a routine version-update PR — handled by Step 4c. Both kinds should be gone by the end.

Step 2: Categorize each alert

For each alert to fix, determine:

  1. Ecosystem: pip or npm
  2. Direct vs transitive: Is the package listed directly in pyproject.toml (or a lib/*/pyproject.toml), or is it only in the lockfile as a transitive dependency?
  3. Manifest location: Which pyproject.toml or package.json owns this dependency?

For pip packages, check all pyproject.toml files:

bash
grep -rn '<package-name>' pyproject.toml lib/*/pyproject.toml

For npm packages, check the manifest path from the alert (usually under vscode_extensions/).

Step 3: Fix pip dependencies

Direct dependencies

If the package appears in a pyproject.toml dependencies or optional dependency group:

  1. Update the version constraint to require at least the patched version:
    "package>=old_version"  →  "package>=patched_version"
  2. Run uv lock --upgrade-package <package> to update the lockfile
Transitive dependencies

If the package is only in uv.lock (not a direct dependency):

  1. Identify which direct dependency pulls it in:
    bash
    uv tree --invert --package <vulnerable-package> --depth 1
  2. Check if any of those parent packages cap the vulnerable package below the patched version. For each parent, check its constraints on PyPI:
    python
    python3 -c "
    import json, urllib.request
    r = urllib.request.urlopen('https://pypi.org/pypi/<parent>/json')
    d = json.loads(r.read())
    deps = d['info'].get('requires_dist') or []
    matches = [dep for dep in deps if '<vulnerable-pkg>' in dep.lower()]
    print(matches)
    "
  3. If no cap blocks it: simply run uv lock --upgrade-package <vulnerable-package>
  4. If a cap blocks it: check if a newer version of the parent package relaxes the cap. If it does, upgrade the parent. If the latest parent still caps it:
    • Check if the parent package is actually used in the codebase (grep -rn 'import <parent>\|from <parent>' --include='*.py')
    • If unused: remove it from pyproject.toml (this unblocks the transitive dep)
    • If used: inform the user that the fix requires either waiting for the parent to update, or adding a [tool.uv] override (explain the tradeoff — overrides can cause runtime incompatibilities)
After removing a dependency

When removing a package, check if it's imported anywhere in the codebase. If it is, replace its usage with an alternative approach. For example, when we removed moviepy, we replaced its ImageSequenceClip usage with a direct ffmpeg subprocess call.

Always search broadly:

bash
rg 'import <package>|from <package>' --type py

Step 4: Fix npm dependencies

For each vulnerable npm package:

  1. Navigate to the directory containing the affected package.json
  2. Update the package:
    bash
    cd <directory>
    npm install  # ensure node_modules exist
    npm install <package>@^<patched-version>
  3. Verify the update:
    bash
    npm ls <package>
npm transitive vs. direct deps

Before adding a package to dependencies, check whether the extension actually imports it:

bash
rg -l "from ['\"]<package>|require\(['\"]<package>" vscode_extensions/<ext>/src
  • Imported in src/ → it's a real runtime dependency; bump it in dependencies (npm install <package>@^<version>).
  • Not imported (it's a dev-tooling transitive dep, e.g. pulled in by eslint/mocha) → do not add it to dependencies (that creates a phantom runtime dep). Instead force the patched version via the existing overrides block in package.json, then npm install. This matches how Dependabot itself fixes those (lockfile-only).
Show full SKILL.md (551 more words)Show less

Step 4c: Clear remaining (non-security) Dependabot version-update PRs

After the security alerts are handled, fold every remaining open Dependabot PR (the ones with no matching alert from Step 1b) into the same batch branch, then close them. These are routine bumps — usually npm devDeps in vscode_extensions/ (e.g. esbuild) or js-yaml in extensions GitHub didn't alert on.

For each remaining PR, apply its bump locally rather than merging the Dependabot branch (keeps everything in one PR with one CI run):

  1. Read the target package + version from the PR title (Bump <pkg> from <old> to <new> in /<path>).
  2. cd into the manifest's directory and apply it the same way as Step 4 (direct bump if imported in src/, overrides if a dev-tooling transitive — see above). For a pure devDependency like esbuild, bump it in devDependencies: npm install -D <pkg>@^<new>.
  3. Verify it resolved: npm ls <pkg>.

After applying all of them, compile each touched extension so a bad bump fails locally, not in CI:

bash
cd vscode_extensions/<ext> && npm run compile   # or `npm run lint` if there's no compile script

Then close each superseded Dependabot PR referencing the batch PR (do this in Step 6, after the batch PR exists):

bash
gh pr close <number> --repo owid/etl --comment \
  "Superseded by #<batch-PR>, which applies this bump as part of a single batched Dependabot sweep. Closing as obsolete."

If a bump is risky or a major version jump with breaking changes, don't force it into the batch — leave that PR open and flag it for the user instead.

Step 5: Verify changes

Run make check-all (lint + format + typecheck across the root and every lib/). The plain make check only covers the top-level codebase, so breaking changes from upgrades to packages used by lib/ (e.g. gdown's fuzzy= removal in lib/datautils/) would slip through.

If it fails, fix the issues (commonly: removed/renamed kwargs that type checkers flag) and re-run until it passes.

Step 5b: Bump lib/ package versions

If you modified any lib/{catalog,datautils,repack}/pyproject.toml, also bump that file's version = "x.y.z" (patch bump). The publish-owid-packages.yml workflow republishes these packages to PyPI on master push and rejects the publish if the version already exists.

After bumping, re-run uv lock (top-level and inside each modified lib/<name>/) so the lockfiles pick up the new version.

Step 6: Create PR

Follow the standard ETL PR workflow:

bash
.venv/bin/etl pr "Fix <severity> Dependabot vulnerabilities" data

Stage and commit all changed files:

  • pyproject.toml and any lib/*/pyproject.toml
  • uv.lock
  • Any modified .py files (from removing unused deps)
  • Any package.json / package-lock.json files

Use commit emoji 🐛🤖 (bug fix, AI-written).

After pushing, post @codex review as a PR comment.

Then close every open Dependabot PR this batch covers — both the security ones (Steps 2–4) and the version-update ones (Step 4c) — with a comment referencing this PR (see the close commands in Steps 1b and 4c). Finally, re-run the Step 1b PR list and confirm it's empty (modulo anything you deliberately left open and flagged for the user). If the title only covers security fixes but you also swept version updates, use a broader title like Fix Dependabot vulnerabilities and clear version-update PRs.

Important notes

  • lib/ contains subdirectories (catalog, datautils, repack, walden) with their own pyproject.toml files — check these too
  • Multiple alerts may reference the same package (e.g. 4 alerts for pytest) — one upgrade fixes them all
  • The uv.lock file may also be affected by [tool.uv] exclude-newer settings in pyproject.toml — if a patched version exists on PyPI but uv won't resolve it, check this setting
  • Some alerts may be auto-dismissed by Dependabot (state auto_dismissed) — skip those
  • When multiple packages need upgrading, batch them: uv lock --upgrade-package pkg1 --upgrade-package pkg2

© owid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/fix-dependabot of owid/etl.

Open the folder on GitHubat commit d5ba5a6

Compare with similar skills

Fix Dependabot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fix Dependabot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fix Dependabot this skillowid/etl159—~2.9kAutomated safety check: PassMIT
Dependabot Alerts Updatelivesession/xyd114—~2kAutomated safety check: PassMIT
Fix Security PRunional/typescript-blackbook133—~1.4kAutomated safety check: WarnMIT
Stash Supply Chain Securitycipherstash/stack157—~5.2kAutomated safety check: WarnMIT
Dependency Update BotVarnan-Tech/opendirectory674—~3kAutomated safety check: NotesMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT

Similar skills

  • Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

    114 GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Fix Security PR

    unional/typescript-blackbook

    Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

    133 GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check: warnings
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Dependency Update Bot

    Varnan-Tech/opendirectory

    Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

    674 GitHub stars~3k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Update Deps

    github/rust-gems

    Official

    Keep dependencies up-to-date. An agent skill from github/rust-gems.

    134 GitHub stars~2.7k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from owid/etl

All 35 skills in this repo
  • Find every OWID surface that references a chart, indicator, MDIM, or explorer — articles (links vs embeds), explorers, narrative charts, data insights, static viz, key-chart slots, MDIM views.

    159 GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Add a scatter view (with GDP per capita on x) to existing OWID charts via the admin API, mirroring the admin UI's "Add scatter type" defaults, then retire the old standalone "X vs.

    159 GitHub stars~19k tokensUpdated today
    Auto-check passed
  • Add new survey question codes (e.g. An agent skill from owid/etl.

    159 GitHub stars~11k tokensUpdated today
    Auto-check: notes
  • Build or refresh an OWID static visualization end to end — resolve what data it needs from an old static viz image, an indicator, or a grapher chart; check both the ETL catalog and the producer's…

    159 GitHub stars~8.3k tokensUpdated today
    Auto-check passed
  • Propose redirects from (soon-to-sunset) grapher charts to the matching views of published MDIMs.

    159 GitHub stars~9.6k tokensUpdated today
    Auto-check: notes
  • Take (soon-to-sunset) OWID explorers to redirected MDIMs, end to end.

    159 GitHub stars~7.3k tokensUpdated today
    Auto-check: notes

Works with

Questions about Fix Dependabot

What does Fix Dependabot do?

Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies. Fix Dependabot is an agent skill from owid/etl. Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.

When should I use Fix Dependabot?

Fix Dependabot fits situations like: the user mentions dependabot; security alerts; dependabot alerts; wants to fix vulnerable packages.

How do I install Fix Dependabot in Claude Code?

Run `npx skills add owid/etl --skill fix-dependabot -a claude-code`. Or copy the skill folder (.claude/skills/fix-dependabot in owid/etl) into .claude/skills/fix-dependabot in your project. Claude Code loads it when a task matches its description.

How do I install Fix Dependabot in Codex?

Run `npx skills add owid/etl --skill fix-dependabot -a codex`. Or copy the skill folder (.claude/skills/fix-dependabot in owid/etl) into .agents/skills/fix-dependabot in your project. Codex loads it when a task matches its description.

Can I use Fix Dependabot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add owid/etl --skill fix-dependabot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-dependabot, .gemini/skills/fix-dependabot, .github/skills/fix-dependabot and .opencode/skills/fix-dependabot in your project.

What does Fix Dependabot need to run?

Going by SKILL.md and its folder, Fix Dependabot needs the command-line tools its instructions call (npm, uv, gh, rg and make). Our summary lists: Python 3; Node.js.

Does Fix Dependabot access the network?

SKILL.md names 1 domain. In commands or code: pypi.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Fix Dependabot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fix Dependabot use?

Fix Dependabot is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fix Dependabot use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fix Dependabot?

Skills that share tags, products or a category with Fix Dependabot: Dependabot Alerts Update (livesession/xyd, 114 stars), Fix Security PR (unional/typescript-blackbook, 133 stars), Stash Supply Chain Security (cipherstash/stack, 157 stars) and Dependency Update Bot (Varnan-Tech/opendirectory, 674 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fix Dependabot?

owid (a GitHub organization) maintains it in owid/etl, which has 159 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 9, 2026.

Source: owid/etl on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.