maintaining-third-party-components
Use when updating, investigating an advisory for a third-party software component governed by a named existing policy, replacing, sealing, retiring, or completing its dependency PR. Includes routine Dependabot work and scheduled or foreign-harness wake-ups; do not use to invent a new trust boundary, silently revise policy, or perform generic Git/PR/review work.
Pinned to revision 4a40c0d3cfa8, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/maintaining-third-party-components/SKILL.md
- skills/maintaining-third-party-components/agents/openai.yaml
- skills/maintaining-third-party-components/references/component-clearance-contract.md
- skills/maintaining-third-party-components/references/component-policy-contract.md
- skills/maintaining-third-party-components/references/invocation-envelope.json
- skills/maintaining-third-party-components/references/scheduler-adapters.json
Every link opens the file at its source, pinned to the revision this page describes.