Agent skill

Gem Dependency Management

by ruby-git in ruby-git/ruby-git

Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.

MITAuto-check passedDevelopment

Install Gem Dependency Management

skills CLI
$ npx skills add ruby-git/ruby-git --skill dependency-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruby-git/ruby-git dependency-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruby-git/ruby-git.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/dependency-management .claude/skills/dependency-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-management
GitHub stars
1.8k
Token cost
~806 tokens
SKILL.md length
355 words
Files
1
Skills in repo
30
Repo updated
First seen
Licence
MIT

At a glance

Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.

  • Works in 4 steps: Assess: Run bundle outdated and bundle… → Update: Edit git.gemspec if constraints… → Test: Run bundle exec rake default -… → …
  • Updating gem dependencies in the ruby-git repository
  • SKILL.md covers Contents, How to use this skill, Related skills and Project-Specific Rules, plus 3 more sections
  • Calls bundle and npx

What it does

This is a project-specific workflow for ruby-git, meant to be attached to a Copilot Chat context and invoked with the update or CVE scope. It sets the rules that all dependencies, runtime and development, go in git.gemspec as Rubocop enforces, that the Gemfile stays minimal or empty, and that Gemfile.lock is not committed because this is a gem library.

The update process has four steps: run bundle outdated and bundle audit check --update where available, edit git.gemspec if constraints change and run bundle update, run bundle exec rake default, which must pass on all supported Ruby versions, then commit using Conventional Commits with fix(deps), chore(deps) or a breaking-change footer. Security fixes come first, constraints are chosen carefully because gem users resolve dependencies independently, and failing tests are isolated by updating one gem at a time or by binary search. Related skills cover CI troubleshooting, TDD development and release management.

When your agent uses it

  • Updating gem dependencies in the ruby-git repository
  • Fixing a CVE reported against a dependency
  • Checking for outdated gems before a release

Example prompts

  • “Run the dependency update workflow and tell me which gems are outdated.”
  • “Fix the CVE that bundle audit reports and prepare the commit message.”
  • “Update the development dependencies in git.gemspec and confirm the default rake task passes.”

Requirements

  • Ruby with Bundler
  • bundler-audit, where available

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Assess: Run bundle outdated and bundle audit check --update (if available)
  2. Update: Edit git.gemspec if constraints need changing, then run bundle update
  3. Test: Run bundle exec rake default - must pass on all supported Ruby versions (see CI matrix in .github/workflows/ and minimum version in…
  4. Commit: Use conventional commit format

What it can do on your machine

Read from SKILL.md and the folder at commit f3bf20f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bundle
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • conventionalcommits.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gem Dependency Management loads about 806 tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 355 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~806

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruby-git/ruby-git at commit f3bf20f, republished under its MIT licence (© ruby-git). 355 words, ~806 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-management/SKILL.md (or your agent's skills folder).
name
dependency-management
description
Updates gem dependencies, handles CVEs, and manages gemspec rules. Use when updating dependencies, checking for outdated gems, or fixing security vulnerabilities.

Dependency Management Workflow

Contents

How to use this skill

Attach this file to your Copilot Chat context, then invoke it with the specific dependency update or CVE remediation scope. Apply this workflow before changing version constraints so updates remain consistent with gem project rules.

Project-Specific Rules

  • All dependencies go in git.gemspec (both runtime and development) - enforced by Rubocop
  • Gemfile should remain minimal/empty - do not add dependencies here
  • Gemfile.lock is NOT committed - this is a gem/library project

Update Process

  1. Assess: Run bundle outdated and bundle audit check --update (if available)
  2. Update: Edit git.gemspec if constraints need changing, then run bundle update
  3. Test: Run bundle exec rake default - must pass on all supported Ruby versions (see CI matrix in .github/workflows/ and minimum version in git.gemspec)
  4. Commit: Use conventional commit format:
    • Security: fix(deps): update <gem> to fix CVE-XXXX-XXXX
    • Regular: chore(deps): update dependencies
    • Breaking: chore(deps)!: update <gem> with BREAKING CHANGE: footer
Show full SKILL.md (160 more words)Show less

Key Considerations

  • Security vulnerabilities are highest priority - address immediately
  • For gem projects, version constraints in gemspec must be carefully chosen since users resolve dependencies independently
  • Breaking changes in dependencies may require code changes (use TDD workflow)
  • Test with both minimum supported versions and latest versions when possible
  • If tests fail, isolate by updating gems one at a time or use binary search

Commit Guidelines

This project uses Conventional Commits. A commit hook enforces the format. See the "Commit message guidelines" section in CONTRIBUTING.md for the full format and allowed types.

Issue and PR references in the body: Do not use #<number> in the commit body — write issue 1000 not issue #1000. A commitlint parser flaw treats any line containing #<number> as a footer token, breaking the body/footer split. To close an issue/PR, use Closes/Fixes/Resolves #<number> in the footer. To merely mention one for context, omit the # and no footer line is needed.

To validate a commit message file before committing:

bash
npx commitlint --format @commitlint/format < commit_msg.txt

© ruby-git, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/dependency-management of ruby-git/ruby-git.

Open the folder on GitHubat commit f3bf20f

Compare with similar skills

Gem Dependency Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gem Dependency Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gem Dependency Management this skillruby-git/ruby-git1.8k—~806Automated safety check: PassMIT
Dependency Update BotVarnan-Tech/opendirectory672—~3kAutomated safety check: NotesMIT
Rigor Add Referencerigortype/rigor106—~2.1kAutomated safety check: PassMPL-2.0
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Ghost Scan Depsghostsecurity/skills408—~1.3kAutomated safety check: NotesApache-2.0
Cve Scansoftspark/ai-toolkit179—~1.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Dependency Update Bot

    Varnan-Tech/opendirectory

    Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

    672 GitHub stars~3k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Rigor Add Reference

    rigortype/rigor

    Add or repair a read-only upstream submodule under references/.

    106 GitHub stars~2.1k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Ghost Scan Deps

    ghostsecurity/skills

    Ghost Security - Software Composition Analysis (SCA) scanner.

    408 GitHub stars~1.3k tokensUpdated 9 days ago
    SecurityAuto-check: notes
  • Cve Scan

    softspark/ai-toolkit

    Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

    179 GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check: notes
  • Sca Audit

    OWASP/secure-agent-playbook

    Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

    186 GitHub stars~494 tokensUpdated 12 days ago
    SecurityAuto-check passed

More from ruby-git/ruby-git

All 30 skills in this repo
  • Addresses unresolved pull request review threads and suppressed (low-confidence) Copilot review comments on the current branch, folds each fix into the…

    1.8k GitHub stars~657 tokensUpdated 5 days ago
    Auto-check passed
  • Breaking Change Analysis

    ruby-git/ruby-git

    Assesses what an API change would break before it is made, finds every usage, documents the impact and plans a deprecation or migration path.

    1.8k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Diagnoses and fixes failing GitHub Actions runs by identifying the failure, fetching only the relevant logs, finding the root cause and reproducing it locally.

    1.8k GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check passed
  • Scaffolds and reviews `Git::Commands::*` classes in the ruby-git library, with unit tests, integration tests and YARD docs, using the Base command architecture.

    1.8k GitHub stars~3k tokensUpdated 5 days ago
    Auto-check passed
  • Migrates a direct command call in Ruby Git's Git::Lib to a Git::Commands class, as part of a Strangler Fig redesign, with a plan, legacy tests and a pull request.

    1.8k GitHub stars~4.4k tokensUpdated 5 days ago
    Auto-check passed
  • Scaffolds and reviews facade methods on Git::Repository in ruby-git, with unit tests, integration tests and YARD documentation.

    1.8k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed

Works with

Questions about Gem Dependency Management

What does Gem Dependency Management do?

Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages. This is a project-specific workflow for ruby-git, meant to be attached to a Copilot Chat context and invoked with the update or CVE scope.lock is not committed because this is a gem library.

When should I use Gem Dependency Management?

Gem Dependency Management fits situations like: updating gem dependencies in the ruby-git repository; fixing a CVE reported against a dependency; checking for outdated gems before a release.

How do I install Gem Dependency Management in Claude Code?

Run `npx skills add ruby-git/ruby-git --skill dependency-management -a claude-code`. Or copy the skill folder (.github/skills/dependency-management in ruby-git/ruby-git) into .claude/skills/dependency-management in your project. Claude Code loads it when a task matches its description.

How do I install Gem Dependency Management in Codex?

Run `npx skills add ruby-git/ruby-git --skill dependency-management -a codex`. Or copy the skill folder (.github/skills/dependency-management in ruby-git/ruby-git) into .agents/skills/dependency-management in your project. Codex loads it when a task matches its description.

Can I use Gem Dependency Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruby-git/ruby-git --skill dependency-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-management, .gemini/skills/dependency-management, .github/skills/dependency-management and .opencode/skills/dependency-management in your project.

What does Gem Dependency Management need to run?

Going by SKILL.md and its folder, Gem Dependency Management needs the command-line tools its instructions call (bundle and npx). Our summary lists: Ruby with Bundler; bundler-audit, where available.

Does Gem Dependency Management access the network?

SKILL.md names 1 domain. As links in the text: conventionalcommits.org. This is read from the text; nothing was executed.

Is Gem Dependency Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gem Dependency Management use?

Gem Dependency Management is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gem Dependency Management use?

About 806 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gem Dependency Management?

Skills that share tags, products or a category with Gem Dependency Management: Dependency Update Bot (Varnan-Tech/opendirectory, 672 stars), Rigor Add Reference (rigortype/rigor, 106 stars), Cyberowlai (karimhabush/cyberowl, 263 stars) and Ghost Scan Deps (ghostsecurity/skills, 408 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gem Dependency Management?

ruby-git (a GitHub organization) maintains it in ruby-git/ruby-git, which has 1,799 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 2, 2026.

Source: ruby-git/ruby-git on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.