deps
Use when hardening a dependency supply chain, pinning versions, adding registry/security flags, or setting up Renovate. Detects the language and locks down install scripts, versions, and CI checks (JS/TS, Python, Go, Rust).
- License
- MIT
- Compatibility
- Any language project; hardens that ecosystem's dependency supply chain (JS/TS best-supported, Python, Go and Rust via references/)
Pinned to revision a7812b928cd3, so it is the text this page describes rather than whatever the author pushed since.
Pre-approved tools experimental
Experimental field. Support varies between clients, so this list is what the author declared, not what your client will enforce.
- Read
- Glob
- Grep
- Write
- Edit
- Bash(nub:*)
- Bash(nubx:*)
- Bash(pnpm:*)
- Bash(pnx:*)
- Bash(npx:*)
- Bash(bunx:*)
- Bash(npm:*)
- Bash(bun:*)
- Bash(yarn:*)
- Bash(uv:*)
- Bash(pip:*)
- Bash(pip-audit:*)
- Bash(go:*)
- Bash(govulncheck:*)
- Bash(cargo:*)
- Bash(cargo-audit:*)
- Bash(cargo-deny:*)
- Bash(gh:*)
- Bash(glab:*)
Files
- skills/deps/SKILL.md
- skills/deps/references/go.md
- skills/deps/references/python.md
- skills/deps/references/rust.md
- skills/deps/rules/dependency-review.md
- skills/deps/rules/package-runner.md
- skills/deps/rules/release-quarantine.md
- skills/deps/rules/renovate.md
- skills/deps/rules/version-pinning.md
Every link opens the file at its source, pinned to the revision this page describes.