Dependency Updater
Asvarox/allkaraoke
Smart dependency management for any language. An agent skill from Asvarox/allkaraoke.
Update Rigor's bundled gems and/or Nix Flake development environment while preserving version constraints.
$ npx skills add rigortype/rigor --skill rigor-dependency-update -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rigortype/rigor rigor-dependency-update --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/rigor-dependency-update .claude/skills/rigor-dependency-update && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "rigor-dependency-update" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-dependency-update into .claude/skills/rigor-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-dependency-update", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-dependency-updateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rigortype/rigor --skill rigor-dependency-update -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rigortype/rigor rigor-dependency-update --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/rigor-dependency-update .agents/skills/rigor-dependency-update && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "rigor-dependency-update" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-dependency-update into .agents/skills/rigor-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-dependency-update", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rigortype/rigor --skill rigor-dependency-update -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rigortype/rigor rigor-dependency-update --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/rigor-dependency-update .cursor/skills/rigor-dependency-update && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "rigor-dependency-update" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-dependency-update into .cursor/skills/rigor-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-dependency-update", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rigortype/rigor.git --path .claude/skills/rigor-dependency-update--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rigortype/rigor --skill rigor-dependency-update -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rigortype/rigor rigor-dependency-update --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/rigor-dependency-update .gemini/skills/rigor-dependency-update && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "rigor-dependency-update" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-dependency-update into .gemini/skills/rigor-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-dependency-update", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rigortype/rigor rigor-dependency-updateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rigortype/rigor --skill rigor-dependency-update -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/rigor-dependency-update .github/skills/rigor-dependency-update && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "rigor-dependency-update" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-dependency-update into .github/skills/rigor-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-dependency-update", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rigortype/rigor --skill rigor-dependency-update -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rigortype/rigor rigor-dependency-update --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/rigor-dependency-update .opencode/skills/rigor-dependency-update && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "rigor-dependency-update" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-dependency-update into .opencode/skills/rigor-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-dependency-update", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
rigor-dependency-updateUpdate Rigor's bundled gems and/or Nix Flake development environment while preserving version constraints.
Rigor Dependency Update is an agent skill from rigortype/rigor. Update Rigor's bundled gems and/or Nix Flake development environment while preserving version constraints. Use for dependency, Gemfile.lock, flake.lock, or nixpkgs updates; not for Ruby-version bumps or references/ submodule updates.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management. It works with Ruby. The repository describes itself as: Inference-first static analysis for Ruby. The licence is MPL-2.0.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 57a67cf. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bundlenixgitmakeghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Rigor Dependency Update loads about 2k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 1,011 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rigortype/rigor at commit 57a67cf, republished under its MPL-2.0 licence (© rigortype). 1,011 words, ~1,963 tokens.
.claude/skills/rigor-dependency-update/SKILL.md (or your agent's skills folder).The project's dependencies live in two independent layers, and the first job is to keep them separate — a single "update the deps" request usually means both, but they are different kinds of change and belong in different commits so history stays legible.
Gemfile.lock. The runtime-affecting layer:
the analyzer's own dependencies (prism, rbs,
language_server-protocol) plus dev tooling (rubocop, rspec,
binpacker, …). Managed with bundle update.flake.lock. The development
layer: the pinned nixpkgs-unstable revision that provisions the dev
shell (make, git base, bundix, the Ruby build inputs). Managed with
nix flake update.Do both by default, but each layer is a self-contained commit, so doing
one alone is fine. Work on a branch and open one PR carrying both
commits (the public-dev workflow — grouped changes go through a PR, not a
direct push to master).
Use bundle / nix commands; never hand-edit a lockfile.
bundle update)See what is available first, then update within the existing gemspec constraints:
nix develop --command bundle outdated
nix develop --command bundle updatebundle update re-resolves every gem to the latest version the
gemspec's existing ranges allow. This is a lockfile refresh only —
git diff Gemfile.lock should show version bumps and nothing structural.
Two judgment calls the resolver makes for you, worth confirming:
bundle outdated
lists a new major (e.g. diff-lcs 2.0) but bundle update keeps the
old one, a transitive constraint is capping it (rspec pins diff-lcs < 2.0). That is correct — leave it. Pulling a major that the gemspec
ranges forbid would require a gemspec range change, which is a
deliberate decision outside this skill (edit the gemspec via
bundle add, verify the new major, land it on its own).Commit subject: Update bundled gems to their latest in-range versions.
Body: list the bumps, note no range change, note any major deliberately
held by a transitive cap.
nix flake update)nix flake updateThis bumps the single nixpkgs input to the latest nixpkgs-unstable
and rewrites only flake.lock. flake.nix is untouched.
The deliberate in-flake pins stay — they are hardcoded in flake.nix
for a reason and each has its own change path, so a dev-environment
refresh must not move them:
mkRuby, currently 4.0.5) — bump via
rigor-ruby-version-bump, not here.2.54.0 overrideAttrs) — an explicit override; bump
individually with a fresh source hash if needed.fetchurl hashes) if a newer waza
release is wanted.Commit subject: Update the Nix Flake dev environment to the latest nixpkgs.
Body: note the old → new nixpkgs date, that only flake.lock moved, and
that the in-flake pins were intentionally left.
A nixpkgs bump rebuilds the Ruby derivation to a new /nix/store path
even when the Ruby version is unchanged (the stdenv/build inputs moved).
The gems already compiled into vendor/bundle are linked against the
old libruby, so the next bundle exec dies with, e.g.:
json-2.20.0/lib/json/ext/parser.bundle:
linked to incompatible /nix/store/<old>-ruby-4.0.5/lib/libruby-4.0.5.dylib (LoadError)Rebuild the native extensions against the new Ruby before verifying:
rm -rf vendor/bundle
nix develop --command bundle install # recompiles native ext against the new Rubyvendor/bundle is gitignored — this is a purely local artifact of the
rebuild, so nothing about it is committed, and CI (which installs fresh
each run) never hits this. It only blocks your local make verify, so
clear it whenever a Flake update leaves bundle exec complaining about an
incompatible libruby.
The rebuild dependency makes the order matter when both layers move:
bundle update, review, commit.nix flake update, commit.rm -rf vendor/bundle && bundle install
(rebuild native ext against the freshly-rebuilt Ruby).make verify — must run after step 3, or the stale extensions fail it.nix develop --command make verify
nix develop --command git diff --checkmake verify (test + lint + check + check-plugins) must be green under
the new toolchain and freshly-compiled gems — it is the proof both
layers are healthy together. Only Gemfile.lock and flake.lock should be
in git status (vendor/bundle stays untracked).
A Gemfile.lock bump can move the release gate's allocation number with no
engine change: the rbs gem supplies the core RBS the engine loads, and the
per-PR "Engine allocations" job cannot see it, because both of its arms run on
one bundle. Measure before and after the update, on the base commit and on the
branch, with nix develop --command make bench-perf or by dispatching the
release gate on each (gh workflow run release-gate.yml --ref <branch>). Put
both allocation numbers and the delta in the PR body: a release cut attributes
its rise from these records (bench/README.md, "Over a release cycle"). A
Flake-only update moves the local Ruby but not CI's, so a local pair is enough
for it.
git push origin HEAD:refs/heads/<branch>
gh pr create --draft --base master --title "Update dependencies: bundled gems + Nix Flake dev environment" \
--body "<the two commits, per-layer>"The PR's ci.yml gate re-runs the full suite on a clean checkout (its own
bundle install), which is the authoritative cross-environment check. The PR
is created --draft and goes Ready (gh pr ready <pr>) only on the user's
explicit instruction to land it, with CI green and no stop instruction standing
(this skill's own landing rule, which docs/agents/contribution-flow.md § "Landing a pull
request" defers to — a GitHub
APPROVE cannot exist on a one-developer repository, so it is not the trigger).
bundle add and verified on
its own, not folded into a lockfile refresh.rigor-ruby-version-bump.references/ submodules — rigor-add-reference.git / waza pins — explicit overrides, bumped
individually with fresh hashes.bundle update (not a hand-edit); git diff Gemfile.lock is
version-only; no gemspec range change; held-back majors left alone.nix flake update; only flake.lock moved; Ruby / git / waza in-flake
pins untouched.rm -rf vendor/bundle && bundle install after the Flake update.make verify green under the new toolchain; git diff --check clean.Update bundled gems to their latest in-range versions and
Update the Nix Flake dev environment to the latest nixpkgs.© rigortype, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/rigor-dependency-update of rigortype/rigor.
Open the folder on GitHubat commit 57a67cf
Rigor Dependency Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Rigor Dependency Update this skillrigortype/rigor | 106 | — | ~2k | Automated safety check: Pass | MPL-2.0 | |
| Dependency UpdaterAsvarox/allkaraoke | 261 | 4 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Breaking Change Analysisruby-git/ruby-git | 1.8k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Dep Auditorlaolaoshiren/claude-code-skills-zh | 878 | — | ~895 | Automated safety check: Pass | MIT | |
| Gem Dependency Managementruby-git/ruby-git | 1.8k | — | ~806 | Automated safety check: Pass | MIT | |
| Dependency Update BotVarnan-Tech/opendirectory | 674 | — | ~3k | Automated safety check: Notes | MIT |
Asvarox/allkaraoke
Smart dependency management for any language. An agent skill from Asvarox/allkaraoke.
ruby-git/ruby-git
Assesses what an API change would break before it is made, finds every usage, documents the impact and plans a deprecation or migration path.
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
ruby-git/ruby-git
Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.
Varnan-Tech/opendirectory
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
sesori-ai/sesori_apps_monorepo
Weekly dependency update workflow for Sesori Apps Monorepo. An agent skill from sesori-ai/sesori_apps_monorepo.
rigortype/rigor
Measure Rigor's baseline drift across the tagged history of a real OSS Ruby project.
rigortype/rigor
Adjudicate a rigor unused report safely before proposing dead-code removal.
rigortype/rigor
Reduce an existing .rigor-baseline.yml rule by rule by triaging sites, fixing or intentionally suppressing them, and regenerating the baseline.
rigortype/rigor
Validate that a project's Rigor configuration, plugins, paths, and baseline are actually healthy.
rigortype/rigor
Author a new Rigor plugin, choosing plugins/ for production support or examples/ for a contract walkthrough.
rigortype/rigor
Author a Rigor plugin in an adopting project or standalone rigor- gem for a DSL, framework, or metaprogramming pattern.
Works with
Categories
Update Rigor's bundled gems and/or Nix Flake development environment while preserving version constraints. Rigor Dependency Update is an agent skill from rigortype/rigor. Update Rigor's bundled gems and/or Nix Flake development environment while preserving version constraints.
Rigor Dependency Update fits situations like: nixpkgs updates; not for Ruby-version bumps; references/ submodule updates.
Run `npx skills add rigortype/rigor --skill rigor-dependency-update -a claude-code`. Or copy the skill folder (.claude/skills/rigor-dependency-update in rigortype/rigor) into .claude/skills/rigor-dependency-update in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rigortype/rigor --skill rigor-dependency-update -a codex`. Or copy the skill folder (.claude/skills/rigor-dependency-update in rigortype/rigor) into .agents/skills/rigor-dependency-update in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rigortype/rigor --skill rigor-dependency-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rigor-dependency-update, .gemini/skills/rigor-dependency-update, .github/skills/rigor-dependency-update and .opencode/skills/rigor-dependency-update in your project.
Going by SKILL.md and its folder, Rigor Dependency Update needs the command-line tools its instructions call (bundle, nix, git, make and gh).
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Rigor Dependency Update is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Rigor Dependency Update: Dependency Updater (Asvarox/allkaraoke, 261 stars), Breaking Change Analysis (ruby-git/ruby-git, 1.8k stars), Dep Auditor (laolaoshiren/claude-code-skills-zh, 878 stars) and Gem Dependency Management (ruby-git/ruby-git, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rigortype (a GitHub organization) maintains it in rigortype/rigor, which has 106 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 8, 2026.
Source: rigortype/rigor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.