akshayrao14/git-practices · Archived

dependabot-triage

Installation

$ npx skills add https://github.com/akshayrao14/git-practices

Summary

  • Triage and fix Dependabot vulnerability alerts in JavaScript/TypeScript repos (Node.js services AND browser frontends). v2.1 workflow with Standard (defensive) and Fast-Track (low-risk) modes — defensive minimal-patched versioning, exposure mapping (Public/API · Client-Bundle · Internal/Dev), CI workflow inspection to detect every PM in play, mandatory lockfile parity check across every PM that touches package.json, changelog scrape with BREAKING/DEPRECATED/MIGRATION flagging, and safety interlock before applying bumps.
  • Fast-Track mode skips changelog + detailed exposure for Internal/Dev or CVSS<7 alerts, but parity check + dual-write are non-negotiable.
  • Covers npm, pnpm, yarn, bun lockfiles.
  • Use when the user shares a Dependabot URL, asks to fix CVEs, or asks which vulnerability to pick first.

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from akshayrao14/git-practices.

npx skills add https://github.com/akshayrao14/git-practices

Browse all from akshayrao14/git-practices

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

License LICENSE
Default branch pre-release
Open issues 2
Status Archived

History

  1. First recorded snapshot · 1 installs