Dependency Updater
Asvarox/allkaraoke
Smart dependency management for any language. An agent skill from Asvarox/allkaraoke.
Update the development Ruby version markers while preserving the supported-version range.
$ npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rigortype/rigor rigor-ruby-version-bump --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/rigor-ruby-version-bump .claude/skills/rigor-ruby-version-bump && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "rigor-ruby-version-bump" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-ruby-version-bump into .claude/skills/rigor-ruby-version-bump/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-ruby-version-bump", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-ruby-version-bumpType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rigortype/rigor rigor-ruby-version-bump --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/rigor-ruby-version-bump .agents/skills/rigor-ruby-version-bump && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "rigor-ruby-version-bump" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-ruby-version-bump into .agents/skills/rigor-ruby-version-bump/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-ruby-version-bump", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rigortype/rigor rigor-ruby-version-bump --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/rigor-ruby-version-bump .cursor/skills/rigor-ruby-version-bump && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "rigor-ruby-version-bump" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-ruby-version-bump into .cursor/skills/rigor-ruby-version-bump/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-ruby-version-bump", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rigortype/rigor.git --path .claude/skills/rigor-ruby-version-bump--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rigortype/rigor rigor-ruby-version-bump --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/rigor-ruby-version-bump .gemini/skills/rigor-ruby-version-bump && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "rigor-ruby-version-bump" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-ruby-version-bump into .gemini/skills/rigor-ruby-version-bump/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-ruby-version-bump", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rigortype/rigor rigor-ruby-version-bumpInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/rigor-ruby-version-bump .github/skills/rigor-ruby-version-bump && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "rigor-ruby-version-bump" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-ruby-version-bump into .github/skills/rigor-ruby-version-bump/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-ruby-version-bump", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rigortype/rigor rigor-ruby-version-bump --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/rigor-ruby-version-bump .opencode/skills/rigor-ruby-version-bump && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "rigor-ruby-version-bump" agent skill from https://github.com/rigortype/rigor/tree/master/.claude/skills/rigor-ruby-version-bump into .opencode/skills/rigor-ruby-version-bump/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rigor-ruby-version-bump", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
rigor-ruby-version-bumpUpdate the development Ruby version markers while preserving the supported-version range.
Rigor Ruby Version Bump is an agent skill from rigortype/rigor. Update the development Ruby version markers while preserving the supported-version range. Use when the user asks to bump Ruby or adopt a new Ruby release; not for changing the gemspec range, CI matrix, or dependency lockfile.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management. It works with Ruby. The repository describes itself as: Inference-first static analysis for Ruby. The licence is MPL-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c7b6b60. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rubynixbundlemakeghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Rigor Ruby Version Bump loads about 2.6k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 1,270 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rigortype/rigor at commit c7b6b60, republished under its MPL-2.0 licence (© rigortype). 1,270 words, ~2,602 tokens.
.claude/skills/rigor-ruby-version-bump/SKILL.md (or your agent's skills folder).Use this skill when the project's Ruby version needs to move (e.g. 4.0.4 → 4.0.5). The version is recorded in several independent places, and the first job is to understand that those places fall into two categories — conflating them is the mistake this skill exists to prevent.
Land the whole change as one commit so the markers never diverge in history.
Bumping every marker to the exact patch couples the development Ruby to the supported-range markers, which breaks CI and force-upgrades contributors. Keep the two groups separate.
Development Ruby — the exact patch the contributor shell runs. Flake-controlled; bump freely to any released patch.
flake.nix — the mkRuby version + re-derived hash..ruby-version — read by rbenv / chruby / asdf and by ruby/setup-ruby in CI..tool-versions — read by asdf / mise; a peer of .ruby-version.AGENTS.md — the Flake Ruby version under "Development Environment".Supported-range markers — express what Ruby the gem supports, not the dev patch. A patch bump MUST NOT touch these.
rigortype.gemspec — required_ruby_version ([">= 4.0.0", "< 4.1"]) — the binding contract for end users.Gemfile — the ruby directive — a range mirroring the gemspec (ruby ">= 4.0.0", "< 4.1"), never an exact patch.Gemfile.lock — the RUBY VERSION block — held at the supported floor (ruby 4.0.0), not the dev patch..github/workflows/ci.yml — the ruby: matrix — a minor series ("4.0"); ruby/setup-ruby resolves the patch.Why the Gemfile directive must be a range, not an exact patch. Bundler treats ruby "x.y.z" as an exact match and aborts every bundle command when the running Ruby differs by even a patch. CI's setup-ruby installs whatever patch it currently ships (often a step behind the newest release), so an exact pin newer than that breaks CI; contributors not yet on the exact patch are likewise force-upgraded. A range — ruby ">= 4.0.0", "< 4.1" — accepts any 4.0.x and keeps the gemspec as the single source of truth for the supported range. Note that an exact ruby "4.0.0" is not a fix either: it would reject the Flake's own newer Ruby and break the dev shell.
The scope depends on which digit moves:
4.0.4 → 4.0.5): development markers only — Steps 1–3. The supported-range markers already admit the new patch; leave them untouched.4.0 → 4.1): Steps 1–3 plus Step 6 — a minor bump is also where the supported-range markers move (gemspec ceiling, Gemfile range, Gemfile.lock floor, ci.yml matrix). The references/ruby submodule tracks branch ruby_4_0 (see .gitmodules) — a minor bump may need that branch repointed.flake.nix (the source of truth for local builds)Edit the mkRuby call:
ruby = (pkgs.mkRuby {
version = pkgs.mkRubyVersion "4" "0" "5" ""; # ← new version digits
hash = "sha256-..."; # ← must be re-derived
cargoHash = "sha256-..."; # ← re-verify (see below)
}).override { docSupport = false; };hash is the sha256 of the Ruby source tarball; it changes every release and cannot be guessed. Derive it with the Nix fake-hash technique:
hash to an all-zero placeholder:hash = "sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=";nix develop --command truehash mismatch with a got: line — copy that value into hash:error: hash mismatch in fixed-output derivation '...ruby-4.0.5.tar.gz.drv':
specified: sha256-AAAA...
got: sha256-fWFJB5pj+K4dMmyfplxgGbotwxVerns5FZgXkRyIlY4=cargoHash (the vendored Rust deps for YJIT) is checked after hash resolves. Across patch releases it is usually unchanged — but verify, never assume: temporarily set it to the all-zero placeholder too and run the shell again. If Nix reports the same value it already had, restore it; if it differs, take the got: value.
Confirm the build:
nix develop --command ruby -v
# => ruby 4.0.5 (...) +PRISM [...].ruby-version and .tool-versionsTwo single-line version files. Set each to the full x.y.z version.
.ruby-version is read by rbenv / chruby / asdf and by ruby/setup-ruby in CI:
4.0.5.tool-versions is the asdf / mise version file — a peer of .ruby-version recording the same development-Ruby patch, prefixed with the tool name:
ruby 4.0.5AGENTS.md — the Flake Ruby versionUnder "Development Environment", update the version in "The Flake owns Ruby 4.0.5 and the vendored vendor/bundle". AGENTS.md states no supported range; that lives in the gemspec (Step 6).
Then grep -rn the old version across docs/ and update live docs (docs/CURRENT_WORK.md). Leave dated records — docs/adr/*, docs/notes/*, and existing CHANGELOG.md entries — untouched: they record a point-in-time fact, not the current target.
nix develop --command make verifymake verify chains test + lint + the rigor check lib self-check. It must stay clean on the new Ruby. bundle exec reads the Gemfile ruby directive — because that directive is a range, the new patch satisfies it without a Gemfile edit.
A Ruby change can move the release gate's allocation number with no engine change, and the per-PR "Engine allocations" job cannot see it, because both of its arms run on one Ruby. The gate runs on CI's Ruby, the ruby-version: "4.0" series ruby/setup-ruby floats to the latest patch in release-gate.yml (the same series as ci.yml), so a patch bump here moves only the Flake's Ruby: run nix develop --command make bench-perf before and after it. A minor bump moves CI's series too: dispatch the release gate on the base and on the branch (gh workflow run release-gate.yml --ref <branch>). Put both allocation numbers and the delta in the PR body; a release cut attributes its rise from these records (bench/README.md, "Over a release cycle").
One commit covering every marker that moved. Subject (plain imperative, no prefix):
Bump development Ruby to 4.0.5Body — note what changed and why the supported-range markers were left alone, e.g.:
Only the development markers move on a patch bump: flake.nix,
.ruby-version, .tool-versions, and the AGENTS.md Flake Ruby version. The Gemfile `ruby`
directive (a >= 4.0.0, < 4.1 range), Gemfile.lock's RUBY VERSION
(held at the 4.0.0 floor), the gemspec range, and the ci.yml
"4.0" minor series are supported-range markers and deliberately
unchanged. flake.lock is unchanged (it pins only the nixpkgs
input).A minor bump is the only time the supported-range markers move. They move together:
rigortype.gemspec — re-evaluate the required_ruby_version range. The ceiling/floor change only when deliberately changing the supported range — a separate decision from the development Ruby.Gemfile — the ruby directive is a range mirroring the gemspec. If the gemspec range changed, update the directive to match. Keep it a range; never an exact patch.Gemfile.lock — the RUBY VERSION block is held at the supported floor. Update it only if the floor moved. Hand-edit it; do not regenerate it from the running Ruby (see below)..github/workflows/ci.yml — the ruby: matrix uses a minor series ("4.0"); ruby/setup-ruby resolves it to the latest patch automatically, so a patch bump needs no change. A minor bump updates the entry ("4.0" → "4.1").Gemfile.lock's RUBY VERSION is not regenerated per bumpBundler writes the RUBY VERSION block from the running Ruby whenever bundle install / bundle lock runs. The project deliberately keeps it at the supported floor (ruby 4.0.0) instead, so the lock stays stable across patch bumps and does not record the dev patch. If a bundle install rewrites it to the running Ruby, reset that block to the floor before committing. bundle exec (what make verify runs) does not rewrite the lock, so a normal verify leaves it alone.
Gemfile, Gemfile.lock, rigortype.gemspec, .github/workflows/ci.yml — supported-range markers; a patch bump leaves all four alone (see Step 6 for when they do move).flake.lock — pins only the nixpkgs input revision. mkRuby takes the version and hash inline, so a Ruby bump never touches the lock. (Refreshing nixpkgs is a separate nix flake update decision.)docs/adr/*, docs/notes/* — dated design records; their version mentions are history.flake.nix — mkRubyVersion digits + re-derived hash; cargoHash verified (not assumed).nix develop --command ruby -v reports the new version..ruby-version — full x.y.z..tool-versions — ruby x.y.z.AGENTS.md Flake Ruby version; live docs/ updated, dated records left alone.Gemfile, Gemfile.lock, rigortype.gemspec, ci.yml — NOT modified.flake.lock — NOT modified.make verify clean on the new Ruby.Bump development Ruby to x.y.z.rigortype.gemspec required_ruby_version range re-evaluated.Gemfile ruby directive range updated to mirror the gemspec (still a range).Gemfile.lock RUBY VERSION updated to the new floor (hand-edited, not regenerated).ci.yml ruby: matrix entry bumped.references/ruby submodule branch repointed if required.© rigortype, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/rigor-ruby-version-bump of rigortype/rigor.
Open the folder on GitHubat commit c7b6b60
Rigor Ruby Version Bump next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Rigor Ruby Version Bump this skillrigortype/rigor | 106 | — | ~2.6k | Automated safety check: Pass | MPL-2.0 | |
| Dependency UpdaterAsvarox/allkaraoke | 261 | 4 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Breaking Change Analysisruby-git/ruby-git | 1.8k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Dep Auditorlaolaoshiren/claude-code-skills-zh | 877 | — | ~895 | Automated safety check: Pass | MIT | |
| Gem Dependency Managementruby-git/ruby-git | 1.8k | — | ~806 | Automated safety check: Pass | MIT | |
| Dependency Update BotVarnan-Tech/opendirectory | 672 | — | ~3k | Automated safety check: Notes | MIT |
Asvarox/allkaraoke
Smart dependency management for any language. An agent skill from Asvarox/allkaraoke.
ruby-git/ruby-git
Assesses what an API change would break before it is made, finds every usage, documents the impact and plans a deprecation or migration path.
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
ruby-git/ruby-git
Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.
Varnan-Tech/opendirectory
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
sesori-ai/sesori_apps_monorepo
Weekly dependency update workflow for Sesori Apps Monorepo. An agent skill from sesori-ai/sesori_apps_monorepo.
rigortype/rigor
Measure Rigor's baseline drift across the tagged history of a real OSS Ruby project.
rigortype/rigor
Adjudicate a rigor unused report safely before proposing dead-code removal.
rigortype/rigor
Reduce an existing .rigor-baseline.yml rule by rule by triaging sites, fixing or intentionally suppressing them, and regenerating the baseline.
rigortype/rigor
Validate that a project's Rigor configuration, plugins, paths, and baseline are actually healthy.
rigortype/rigor
Author a new Rigor plugin, choosing plugins/ for production support or examples/ for a contract walkthrough.
rigortype/rigor
Author a Rigor plugin in an adopting project or standalone rigor- gem for a DSL, framework, or metaprogramming pattern.
Works with
Categories
Update the development Ruby version markers while preserving the supported-version range. Rigor Ruby Version Bump is an agent skill from rigortype/rigor. Update the development Ruby version markers while preserving the supported-version range.
Rigor Ruby Version Bump fits situations like: the user asks to bump Ruby; adopt a new Ruby release; not for changing the gemspec range; dependency lockfile.
Run `npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a claude-code`. Or copy the skill folder (.claude/skills/rigor-ruby-version-bump in rigortype/rigor) into .claude/skills/rigor-ruby-version-bump in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a codex`. Or copy the skill folder (.claude/skills/rigor-ruby-version-bump in rigortype/rigor) into .agents/skills/rigor-ruby-version-bump in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rigor-ruby-version-bump, .gemini/skills/rigor-ruby-version-bump, .github/skills/rigor-ruby-version-bump and .opencode/skills/rigor-ruby-version-bump in your project.
Going by SKILL.md and its folder, Rigor Ruby Version Bump needs the command-line tools its instructions call (ruby, nix, bundle, make and gh).
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Rigor Ruby Version Bump is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Rigor Ruby Version Bump: Dependency Updater (Asvarox/allkaraoke, 261 stars), Breaking Change Analysis (ruby-git/ruby-git, 1.8k stars), Dep Auditor (laolaoshiren/claude-code-skills-zh, 877 stars) and Gem Dependency Management (ruby-git/ruby-git, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rigortype (a GitHub organization) maintains it in rigortype/rigor, which has 106 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 2, 2026.
Source: rigortype/rigor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.