Dependency Update Bot
Varnan-Tech/opendirectory
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.
$ npx skills add ruby-git/ruby-git --skill dependency-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ruby-git/ruby-git dependency-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ruby-git/ruby-git.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/dependency-management .claude/skills/dependency-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-management" agent skill from https://github.com/ruby-git/ruby-git/tree/main/.github/skills/dependency-management into .claude/skills/dependency-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ruby-git/ruby-git/tree/main/.github/skills/dependency-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ruby-git/ruby-git --skill dependency-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ruby-git/ruby-git dependency-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ruby-git/ruby-git.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/dependency-management .agents/skills/dependency-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-management" agent skill from https://github.com/ruby-git/ruby-git/tree/main/.github/skills/dependency-management into .agents/skills/dependency-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ruby-git/ruby-git --skill dependency-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ruby-git/ruby-git dependency-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ruby-git/ruby-git.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/dependency-management .cursor/skills/dependency-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-management" agent skill from https://github.com/ruby-git/ruby-git/tree/main/.github/skills/dependency-management into .cursor/skills/dependency-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ruby-git/ruby-git.git --path .github/skills/dependency-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ruby-git/ruby-git --skill dependency-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ruby-git/ruby-git dependency-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ruby-git/ruby-git.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/dependency-management .gemini/skills/dependency-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-management" agent skill from https://github.com/ruby-git/ruby-git/tree/main/.github/skills/dependency-management into .gemini/skills/dependency-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ruby-git/ruby-git dependency-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ruby-git/ruby-git --skill dependency-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ruby-git/ruby-git.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/dependency-management .github/skills/dependency-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-management" agent skill from https://github.com/ruby-git/ruby-git/tree/main/.github/skills/dependency-management into .github/skills/dependency-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ruby-git/ruby-git --skill dependency-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ruby-git/ruby-git dependency-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ruby-git/ruby-git.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/dependency-management .opencode/skills/dependency-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-management" agent skill from https://github.com/ruby-git/ruby-git/tree/main/.github/skills/dependency-management into .opencode/skills/dependency-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-managementWorkflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.
This is a project-specific workflow for ruby-git, meant to be attached to a Copilot Chat context and invoked with the update or CVE scope. It sets the rules that all dependencies, runtime and development, go in git.gemspec as Rubocop enforces, that the Gemfile stays minimal or empty, and that Gemfile.lock is not committed because this is a gem library.
The update process has four steps: run bundle outdated and bundle audit check --update where available, edit git.gemspec if constraints change and run bundle update, run bundle exec rake default, which must pass on all supported Ruby versions, then commit using Conventional Commits with fix(deps), chore(deps) or a breaking-change footer. Security fixes come first, constraints are chosen carefully because gem users resolve dependencies independently, and failing tests are isolated by updating one gem at a time or by binary search. Related skills cover CI troubleshooting, TDD development and release management.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f3bf20f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bundlenpxFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
conventionalcommits.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gem Dependency Management loads about 806 tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 355 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ruby-git/ruby-git at commit f3bf20f, republished under its MIT licence (© ruby-git). 355 words, ~806 tokens.
.claude/skills/dependency-management/SKILL.md (or your agent's skills folder).Attach this file to your Copilot Chat context, then invoke it with the specific dependency update or CVE remediation scope. Apply this workflow before changing version constraints so updates remain consistent with gem project rules.
git.gemspec (both runtime and development) - enforced by RubocopGemfile should remain minimal/empty - do not add dependencies hereGemfile.lock is NOT committed - this is a gem/library projectbundle outdated and bundle audit check --update (if available)git.gemspec if constraints need changing, then run bundle updatebundle exec rake default - must pass on all supported Ruby versions (see CI matrix in .github/workflows/ and minimum version in git.gemspec)fix(deps): update <gem> to fix CVE-XXXX-XXXXchore(deps): update dependencieschore(deps)!: update <gem> with BREAKING CHANGE: footerThis project uses Conventional Commits. A
commit hook enforces the format. See the "Commit message guidelines" section in
CONTRIBUTING.md for the full format and allowed types.
Issue and PR references in the body: Do not use #<number> in the commit
body — write issue 1000 not issue #1000. A commitlint parser flaw treats any
line containing #<number> as a footer token, breaking the body/footer split. To
close an issue/PR, use Closes/Fixes/Resolves #<number> in the footer. To
merely mention one for context, omit the # and no footer line is needed.
To validate a commit message file before committing:
npx commitlint --format @commitlint/format < commit_msg.txt© ruby-git, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/dependency-management of ruby-git/ruby-git.
Open the folder on GitHubat commit f3bf20f
Gem Dependency Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gem Dependency Management this skillruby-git/ruby-git | 1.8k | — | ~806 | Automated safety check: Pass | MIT | |
| Dependency Update BotVarnan-Tech/opendirectory | 672 | — | ~3k | Automated safety check: Notes | MIT | |
| Rigor Add Referencerigortype/rigor | 106 | — | ~2.1k | Automated safety check: Pass | MPL-2.0 | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Ghost Scan Depsghostsecurity/skills | 408 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Cve Scansoftspark/ai-toolkit | 179 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 |
Varnan-Tech/opendirectory
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
rigortype/rigor
Add or repair a read-only upstream submodule under references/.
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
ghostsecurity/skills
Ghost Security - Software Composition Analysis (SCA) scanner.
softspark/ai-toolkit
Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).
OWASP/secure-agent-playbook
Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.
ruby-git/ruby-git
Addresses unresolved pull request review threads and suppressed (low-confidence) Copilot review comments on the current branch, folds each fix into the…
ruby-git/ruby-git
Assesses what an API change would break before it is made, finds every usage, documents the impact and plans a deprecation or migration path.
ruby-git/ruby-git
Diagnoses and fixes failing GitHub Actions runs by identifying the failure, fetching only the relevant logs, finding the root cause and reproducing it locally.
ruby-git/ruby-git
Scaffolds and reviews `Git::Commands::*` classes in the ruby-git library, with unit tests, integration tests and YARD docs, using the Base command architecture.
ruby-git/ruby-git
Migrates a direct command call in Ruby Git's Git::Lib to a Git::Commands class, as part of a Strangler Fig redesign, with a plan, legacy tests and a pull request.
ruby-git/ruby-git
Scaffolds and reviews facade methods on Git::Repository in ruby-git, with unit tests, integration tests and YARD documentation.
Categories
Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages. This is a project-specific workflow for ruby-git, meant to be attached to a Copilot Chat context and invoked with the update or CVE scope.lock is not committed because this is a gem library.
Gem Dependency Management fits situations like: updating gem dependencies in the ruby-git repository; fixing a CVE reported against a dependency; checking for outdated gems before a release.
Run `npx skills add ruby-git/ruby-git --skill dependency-management -a claude-code`. Or copy the skill folder (.github/skills/dependency-management in ruby-git/ruby-git) into .claude/skills/dependency-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ruby-git/ruby-git --skill dependency-management -a codex`. Or copy the skill folder (.github/skills/dependency-management in ruby-git/ruby-git) into .agents/skills/dependency-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruby-git/ruby-git --skill dependency-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-management, .gemini/skills/dependency-management, .github/skills/dependency-management and .opencode/skills/dependency-management in your project.
Going by SKILL.md and its folder, Gem Dependency Management needs the command-line tools its instructions call (bundle and npx). Our summary lists: Ruby with Bundler; bundler-audit, where available.
SKILL.md names 1 domain. As links in the text: conventionalcommits.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Gem Dependency Management is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 806 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Gem Dependency Management: Dependency Update Bot (Varnan-Tech/opendirectory, 672 stars), Rigor Add Reference (rigortype/rigor, 106 stars), Cyberowlai (karimhabush/cyberowl, 263 stars) and Ghost Scan Deps (ghostsecurity/skills, 408 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ruby-git (a GitHub organization) maintains it in ruby-git/ruby-git, which has 1,799 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 2, 2026.
Source: ruby-git/ruby-git on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.