Dependency Management — Production Patterns
Modern Best Practices (January 2026): Lockfile-first workflows, automated security scanning (Dependabot, Snyk, Socket.dev), semantic versioning, minimal dependencies principle, monorepo workspaces (pnpm, Nx, Turborepo), supply chain security (SBOM, AI BOM, Sigstore), reproducible builds, and AI-generated code validation.
When to Use This Skill
The agent should invoke this skill when a user requests:
- Adding new dependencies to a project
- Updating existing dependencies safely
- Resolving dependency conflicts or version mismatches
- Auditing dependencies for security vulnerabilities
- Understanding lockfile management and reproducible builds
- Setting up monorepo workspaces (pnpm, npm, yarn)
- Managing transitive dependencies and overrides
- Choosing between similar packages (bundle size, maintenance, security)
- Dependency version constraints and semantic versioning
- Dependency security best practices and supply chain security
- Troubleshooting "dependency hell" scenarios
- Package manager configuration and optimization
- Creating reproducible builds across environments
Quick Reference
| Task |
Tool/Command |
Key Action |
When to Use |
| Install from lockfile |
npm ci, poetry install, cargo build |
Clean install, reproducible |
CI/CD, production deployments |
| Add dependency |
npm install <pkg>, poetry add <pkg> |
Updates lockfile automatically |
New feature needs library |
| Update dependencies |
npm update, poetry update, cargo update |
Updates within version constraints |
Monthly/quarterly maintenance |
| Check for vulnerabilities |
npm audit, pip-audit, cargo audit |
Scans for known CVEs |
Before releases, weekly |
| View dependency tree |
npm ls, pnpm why, pipdeptree |
Shows transitive dependencies |
Debugging conflicts |
| Override transitive dep |
overrides (npm), pnpm.overrides |
Force specific version |
Security patch, conflict resolution |
| Monorepo setup |
pnpm workspaces, npm workspaces |
Shared dependencies, cross-linking |
Multi-package projects |
| Check outdated |
npm outdated, poetry show --outdated |
Lists available updates |
Planning update sprints |
Decision Tree: Dependency Management
User needs: [Dependency Task]
├─ Adding new dependency?
│ ├─ Check: Do I really need this? (Can implement in <100 LOC?)
│ ├─ Check: Is it well-maintained? (Last commit <6 months, >10k downloads/week)
│ ├─ Check: Bundle size impact? (Use Bundlephobia for JS)
│ ├─ Check: Security risks? (`npm audit`, Snyk)
│ └─ If all checks pass → Add with `npm install <pkg>` → Commit lockfile
│
├─ Updating dependencies?
│ ├─ Security vulnerability? → `npm audit fix` → Test → Deploy immediately
│ ├─ Routine update?
│ ├─ Patch versions → `npm update` → Safe, do frequently
│ ├─ Minor/major → Check CHANGELOG → Test in staging → Update gradually
│ └─ All at once → [FAIL] RISKY → Update in batches instead
│
├─ Dependency conflict?
│ ├─ Transitive dependency issue?
│ ├─ View tree: `npm ls <package>`
│ ├─ Use overrides sparingly: `overrides` in package.json
│ └─ Document why override is needed
│ └─ Peer dependency mismatch?
│ └─ Check version compatibility → Update parent or child
│
├─ Monorepo project?
│ ├─ Use pnpm workspaces (recommended default)
│ ├─ Shared deps → Root package.json
│ ├─ Package-specific → Package directories
│ └─ Use Nx or Turborepo for task caching
│
└─ Choosing package manager?
├─ New JS project → **pnpm** (recommended default) or **Bun** (often faster; verify ecosystem maturity)
├─ Enterprise monorepo → **pnpm** (mature workspace support)
├─ Speed-focused experimentation → **Bun** (verify ecosystem maturity)
├─ Existing npm project → Migrate to pnpm or stay (check team preference)
├─ Python → **uv** (fast), Poetry (mature), pip+venv (simple)
└─ Data science → **conda** or **uv** (faster environment setup)
Navigation: Core Patterns
Lockfile Management
references/lockfile-management.md
Lockfiles ensure reproducible builds by recording exact versions of all dependencies (direct + transitive). Essential for preventing "works on my machine" issues.
- Golden rules (always commit, never edit manually, regenerate on changes)
- Commands by ecosystem (npm ci, poetry install, cargo build)
- Troubleshooting lockfile conflicts
- CI/CD integration patterns
Semantic Versioning (SemVer)
references/semver-guide.md
Understanding version constraints (^, ~, exact) and how to specify dependency ranges safely.
- SemVer format (MAJOR.MINOR.PATCH)
- Version constraint syntax (caret, tilde, exact)
- Recommended strategies by project type
- Cross-ecosystem version management
Dependency Security Auditing
references/security-scanning.md
Automated security scanning, vulnerability management, and supply chain security best practices.
- Automated tools (Dependabot, Snyk, GitHub Advanced Security)
- Running audits (npm audit, pip-audit, cargo audit)
- CI integration and alert configuration
- Incident response workflows
Dependency Selection
references/dependency-selection-guide.md
Deciding whether to add a new dependency and choosing between similar packages.
- Minimal dependencies principle (best dependency is the one you don't add)
- Evaluation checklist (maintenance, bundle size, security, alternatives)
- Choosing between similar packages (comparison matrix)
- When to reject a dependency
Update Strategies
references/update-strategies.md
Keeping dependencies up to date safely while minimizing breaking changes and security risks.
- Update strategies (continuous, scheduled, security-only)
- Safe update workflow (check outdated, categorize risk, test, deploy)
- Automated update tools (Dependabot, Renovate, npm-check-updates)
- Handling breaking changes and rollback plans
Monorepo Management
references/monorepo-patterns.md
Managing multiple related packages in a single repository with shared dependencies.
- Workspace tools (pnpm, npm, yarn workspaces)
- Monorepo structure and organization
- Build optimization (Nx, Turborepo)
- Versioning and publishing strategies
Transitive Dependencies
references/transitive-dependencies.md
Dealing with dependencies of your dependencies (indirect dependencies).
- Viewing dependency trees (npm ls, pnpm why, pipdeptree)
- Resolving transitive conflicts (overrides, resolutions, constraints)
- Security risks and version conflicts
- Best practices (use sparingly, document, test)
Ecosystem-Specific Guides
references/ecosystem-guides.md
Language and package-manager-specific best practices.
- Node.js (npm, yarn, pnpm comparison and best practices)
- Python (pip, poetry, conda)
- Rust (cargo), Go (go mod), Java (maven, gradle)
- PHP (composer), .NET (nuget)
Anti-Patterns
references/anti-patterns.md
Common mistakes to avoid when managing dependencies.
- Critical anti-patterns (not committing lockfiles, wildcards, ignoring audits)
- Dangerous anti-patterns (never updating, deprecated packages)
- Moderate anti-patterns (overusing overrides, ignoring peer deps)
Navigation: Templates
Node.js
assets/nodejs/
package-json-template.json - Production-ready package.json with best practices
npmrc-template.txt - Team configuration for npm
pnpm-workspace-template.yaml - Monorepo workspace setup
Python
assets/python/
pyproject-toml-template.toml - Poetry configuration with best practices
Automation
assets/automation/
dependabot-config.yml - GitHub Dependabot configuration
renovate-config.json - Renovate Bot configuration
audit-checklist.md - Security audit workflow
template-supply-chain-security.md - NEW SBOM, provenance, vulnerability management
template-dependency-upgrade-playbook.md - Upgrade batching, rollout, rollback
template-sbom-vuln-triage-checklist.md - SBOM mapping + vulnerability triage
Supply Chain Security
assets/automation/template-supply-chain-security.md — Production-grade dependency security.
Related templates:
- assets/automation/template-dependency-upgrade-playbook.md
- assets/automation/template-sbom-vuln-triage-checklist.md
Key Sections
- SBOM Generation — CycloneDX, SPDX formats; CI/CD integration
- AI BOM (Emerging) — Extended SBOM for AI-native systems (models, datasets, training artifacts)
- Provenance & Attestation — SLSA levels, Sigstore signing, npm provenance
- Vulnerability Management — Triage workflow, severity SLAs, scanning tools
- Upgrade Playbooks — Batching strategy, rollback procedures
- Pinning & Reproducibility — Lockfiles, hash pinning, version constraints
- EU Cyber Resilience Act — SBOM requirements effective Dec 2027
Do / Avoid
GOOD: Do
- Generate SBOM for every release
- Sign release artifacts (Sigstore/cosign)
- Run vulnerability scans in CI/CD
- Fix critical vulnerabilities within 24 hours
- Use lockfiles for reproducible builds
- Verify npm package provenance
- Batch non-security updates by risk level
BAD: Avoid
- Publishing without SBOM
- Using unsigned packages in production
- Ignoring vulnerability scanner output
- Updating all dependencies at once
- Using wildcard version ranges (
*, >=)
- Committing without updating lockfile
- Bypassing security gates "just this once"
Anti-Patterns
| Anti-Pattern |
Problem |
Fix |
| No SBOM |
Can't respond to supply chain attacks |
Generate SBOM in CI/CD |
| Unsigned artifacts |
Tampering undetectable |
Sign with Sigstore |
| Floating versions |
Build not reproducible |
Use lockfiles + exact versions |
| All-at-once updates |
Hard to bisect regressions |
Batch by risk level |
| npm install in CI |
Non-deterministic |
Use npm ci |
| No audit gate |
Vulnerabilities ship to prod |
Gate deployments on audit |
AI-Generated Dependency Risks
WARNING: AI coding agents can introduce vulnerable or non-existent packages at scale (Endor Labs, 2025).
The Problem
AI tools accelerate coding but introduce supply chain risks:
- Hallucinated packages — AI suggests packages that don't exist (typosquatting vectors)
- Vulnerable dependencies — AI recommends outdated or CVE-affected versions
- Unnecessary dependencies — AI over-relies on packages for simple tasks
Best Practices
| Do |
Don't |
| Treat AI-generated code as untrusted third-party input |
Blindly accept AI dependency suggestions |
| Enforce same SAST/SCA scanning for AI-generated code |
Skip security review for "AI-written" code |
| Verify all AI-suggested packages actually exist |
Trust AI to know current package versions |
| Integrate security tools into AI workflows (MCP) |
Allow AI to add dependencies without review |
| Vet MCP servers as part of supply chain |
Use unvetted AI integrations |
Validation Checklist
Before accepting AI-suggested dependencies:
Optional: AI/Automation
Note: AI assists with triage but security decisions need human judgment.
- Automated PR triage — Categorize dependency updates by risk
- Changelog summarization — Summarize breaking changes in updates
- Vulnerability correlation — Link CVEs to affected packages
Bounded Claims
- AI cannot determine business risk acceptance
- Automated fixes require security team review
- Vulnerability severity context needs human validation
Quick Decision Matrix
| Scenario |
Recommendation |
| Adding new dependency |
Check Bundlephobia, npm audit, weekly downloads, last commit |
| Updating dependencies |
Use npm outdated, update in batches, test in staging |
| Security vulnerability found |
Use npm audit fix, review CHANGELOG, test, deploy immediately |
| Monorepo setup |
Use pnpm workspaces or Nx/Turborepo for build caching |
| Transitive conflict |
Use overrides sparingly, document why, test thoroughly |
| Choosing JS package manager |
pnpm (fastest, disk-efficient), Bun (7× faster), npm (most compatible) |
| Python environment |
uv (10-100× faster), Poetry (mature), pip+venv (simple), conda (data science) |
Core Principles
1. Always Commit Lockfiles
Lockfiles ensure reproducible builds across environments. Never add them to .gitignore.
Exception: Don't commit Cargo.lock for Rust libraries (only for applications).
2. Use Semantic Versioning
Use caret (^) for most dependencies, exact versions for mission-critical, avoid wildcards (*).
{
"dependencies": {
"express": "^4.18.0", // Allows patches and minors
"critical-lib": "1.2.3" // Exact for critical
}
}
3. Audit Dependencies Regularly
Run security audits weekly, fix critical vulnerabilities immediately.
npm audit
npm audit fix
4. Minimize Dependencies
The best dependency is the one you don't add. Ask: Can I implement this in <100 LOC?
5. Update Regularly
Update monthly or quarterly. Don't let technical debt accumulate.
npm outdated
npm update
6. Use Overrides Sparingly
Only override transitive dependencies for security patches or conflicts. Document why.
{
"overrides": {
"axios": "1.6.0" // CVE-2023-xxxxx fix
}
}
Related Skills
For complementary workflows and deeper dives:
dev-api-design - API versioning strategies, dependency injection patterns
git-workflow - Git workflows for managing lockfile conflicts, branching strategies
qa-testing-strategy - Testing strategies for dependency updates, integration testing
software-security-appsec - OWASP Top 10, cryptography standards, authentication patterns
ops-devops-platform - CI/CD pipelines, Docker containerization, DevSecOps, deployment automation
docs-codebase - Documenting dependency choices, ADRs, changelogs
External Resources
See data/sources.json for curated resources:
- Package managers: npm, pnpm, Yarn, pip, Poetry, Cargo, Go modules, Maven, Composer
- Semantic versioning: SemVer spec, version calculators, constraint references
- Security tools: Snyk, Dependabot, GitHub Advanced Security, OWASP Dependency-Check, pip-audit, cargo-audit, Socket.dev, Renovate
- Lockfile management: Official docs for package-lock.json, poetry.lock, Cargo.lock, pnpm-lock.yaml
- Monorepo tools: pnpm workspaces, npm workspaces, Yarn workspaces, Nx, Turborepo, Lerna, Bazel
- Analysis tools: Bundlephobia, npm-check-updates, depcheck, pipdeptree, cargo tree
- Supply chain security: SLSA framework, SBOM (CISA), Sigstore, npm provenance, OpenSSF Scorecard
- Best practices: npm/Poetry/Cargo guides, ACM Queue articles, dependency hell references
- Version management: nvm, pyenv, rustup, asdf
- Learning resources: npm guides, Python Packaging User Guide, Rust Book, Monorepo.tools
Usage Notes
For Codex / Claude Code:
- Use this skill when users need dependency management guidance
- Reference specific resources based on the task (lockfiles, security, updates)
- Provide ecosystem-specific guidance (Node.js, Python, Rust)
- Always recommend security audits and reproducible builds
- Encourage minimal dependencies and regular updates
- Link to templates for common configurations
Best Practices:
- Always commit lockfiles (except Cargo.lock for libraries)
- Use semantic versioning (caret for most deps, exact for critical)
- Audit dependencies weekly (
npm audit, pip-audit, cargo audit)
- Update dependencies monthly or quarterly (not all at once)
- Choose package manager based on project needs (pnpm for speed, Poetry for Python apps)
- Document dependency choices in ADRs (Architecture Decision Records)
Success Criteria: Dependencies are minimal, well-maintained, secure, reproducible across environments, and regularly audited for vulnerabilities.
Trend Awareness Protocol
IMPORTANT: When users ask recommendation questions about package managers, dependency tools, or supply chain security, you MUST use WebSearch to check current trends before answering.
Trigger Conditions
- "What's the best package manager for [ecosystem]?"
- "What should I use for [dependency management/security]?"
- "What's the latest in dependency management?"
- "Current best practices for [npm/pnpm/Poetry]?"
- "Is [tool/approach] still relevant in 2026?"
- "[pnpm] vs [npm] vs [yarn]?"
- "Best dependency security scanner?"
Required Searches
- Search:
"dependency management best practices 2026"
- Search:
"[specific tool] vs alternatives 2026"
- Search:
"supply chain security trends January 2026"
- Search:
"[package manager] features 2026"
What to Report
After searching, provide:
- Current landscape: What dependency tools are popular NOW
- Emerging trends: New package managers, security tools, or patterns gaining traction
- Deprecated/declining: Tools/approaches losing relevance or support
- Recommendation: Based on fresh data, not just static knowledge
Example Topics (verify with fresh search)
- Package managers (pnpm, npm, yarn, Poetry, uv for Python)
- Security scanning (Snyk, Dependabot, Socket.dev)
- Supply chain security (SBOM, Sigstore, SLSA)
- Monorepo tools (Nx, Turborepo, Bazel)
- Lockfile and reproducibility patterns
- Automated dependency updates (Renovate, Dependabot)
1---2name: dev-dependency-management3description: Package and dependency management patterns across ecosystems (npm, pip, cargo, maven). Covers lockfiles, semantic versioning, dependency security scanning, update strategies, monorepo workspaces, transitive dependencies, and avoiding dependency hell.4---5
6# Dependency Management — Production Patterns
7
8**Modern Best Practices (January 2026)**: Lockfile-first workflows, automated security scanning (Dependabot, Snyk, Socket.dev), semantic versioning, minimal dependencies principle, monorepo workspaces (pnpm, Nx, Turborepo), supply chain security (SBOM, AI BOM, Sigstore), reproducible builds, and AI-generated code validation.
9
10---
11
12## When to Use This Skill
13
14The agent should invoke this skill when a user requests:
15
16- Adding new dependencies to a project
17- Updating existing dependencies safely
18- Resolving dependency conflicts or version mismatches
19- Auditing dependencies for security vulnerabilities
20- Understanding lockfile management and reproducible builds
21- Setting up monorepo workspaces (pnpm, npm, yarn)
22- Managing transitive dependencies and overrides
23- Choosing between similar packages (bundle size, maintenance, security)
24- Dependency version constraints and semantic versioning
25- Dependency security best practices and supply chain security
26- Troubleshooting "dependency hell" scenarios
27- Package manager configuration and optimization
28- Creating reproducible builds across environments
29
30---
31
32## Quick Reference
33
34| Task | Tool/Command | Key Action | When to Use |
35|------|--------------|------------|-------------|
36| **Install from lockfile** | `npm ci`, `poetry install`, `cargo build` | Clean install, reproducible | CI/CD, production deployments |
37| **Add dependency** | `npm install <pkg>`, `poetry add <pkg>` | Updates lockfile automatically | New feature needs library |
38| **Update dependencies** | `npm update`, `poetry update`, `cargo update` | Updates within version constraints | Monthly/quarterly maintenance |
39| **Check for vulnerabilities** | `npm audit`, `pip-audit`, `cargo audit` | Scans for known CVEs | Before releases, weekly |
40| **View dependency tree** | `npm ls`, `pnpm why`, `pipdeptree` | Shows transitive dependencies | Debugging conflicts |
41| **Override transitive dep** | `overrides` (npm), `pnpm.overrides` | Force specific version | Security patch, conflict resolution |
42| **Monorepo setup** | `pnpm workspaces`, `npm workspaces` | Shared dependencies, cross-linking | Multi-package projects |
43| **Check outdated** | `npm outdated`, `poetry show --outdated` | Lists available updates | Planning update sprints |
44
45---
46
47## Decision Tree: Dependency Management
48
49```text
50User needs: [Dependency Task]
51 ├─ Adding new dependency?
52 │ ├─ Check: Do I really need this? (Can implement in <100 LOC?)
53 │ ├─ Check: Is it well-maintained? (Last commit <6 months, >10k downloads/week)
54 │ ├─ Check: Bundle size impact? (Use Bundlephobia for JS)
55 │ ├─ Check: Security risks? (`npm audit`, Snyk)
56 │ └─ If all checks pass → Add with `npm install <pkg>` → Commit lockfile
57 │
58 ├─ Updating dependencies?
59 │ ├─ Security vulnerability? → `npm audit fix` → Test → Deploy immediately
60 │ ├─ Routine update?
61 │ ├─ Patch versions → `npm update` → Safe, do frequently
62 │ ├─ Minor/major → Check CHANGELOG → Test in staging → Update gradually
63 │ └─ All at once → [FAIL] RISKY → Update in batches instead
64 │
65 ├─ Dependency conflict?
66 │ ├─ Transitive dependency issue?
67 │ ├─ View tree: `npm ls <package>`
68 │ ├─ Use overrides sparingly: `overrides` in package.json
69 │ └─ Document why override is needed
70 │ └─ Peer dependency mismatch?
71 │ └─ Check version compatibility → Update parent or child
72 │
73 ├─ Monorepo project?
74 │ ├─ Use pnpm workspaces (recommended default)
75 │ ├─ Shared deps → Root package.json
76 │ ├─ Package-specific → Package directories
77 │ └─ Use Nx or Turborepo for task caching
78 │
79 └─ Choosing package manager?
80 ├─ New JS project → **pnpm** (recommended default) or **Bun** (often faster; verify ecosystem maturity)
81 ├─ Enterprise monorepo → **pnpm** (mature workspace support)
82 ├─ Speed-focused experimentation → **Bun** (verify ecosystem maturity)
83 ├─ Existing npm project → Migrate to pnpm or stay (check team preference)
84 ├─ Python → **uv** (fast), Poetry (mature), pip+venv (simple)
85 └─ Data science → **conda** or **uv** (faster environment setup)
86```
87
88---
89
90## Navigation: Core Patterns
91
92### Lockfile Management
93
94**[`references/lockfile-management.md`](references/lockfile-management.md)**
95
96Lockfiles ensure reproducible builds by recording exact versions of all dependencies (direct + transitive). Essential for preventing "works on my machine" issues.
97
98- Golden rules (always commit, never edit manually, regenerate on changes)
99- Commands by ecosystem (npm ci, poetry install, cargo build)
100- Troubleshooting lockfile conflicts
101- CI/CD integration patterns
102
103### Semantic Versioning (SemVer)
104
105**[`references/semver-guide.md`](references/semver-guide.md)**
106
107Understanding version constraints (`^`, `~`, exact) and how to specify dependency ranges safely.
108
109- SemVer format (MAJOR.MINOR.PATCH)
110- Version constraint syntax (caret, tilde, exact)
111- Recommended strategies by project type
112- Cross-ecosystem version management
113
114### Dependency Security Auditing
115
116**[`references/security-scanning.md`](references/security-scanning.md)**
117
118Automated security scanning, vulnerability management, and supply chain security best practices.
119
120- Automated tools (Dependabot, Snyk, GitHub Advanced Security)
121- Running audits (npm audit, pip-audit, cargo audit)
122- CI integration and alert configuration
123- Incident response workflows
124
125### Dependency Selection
126
127**[`references/dependency-selection-guide.md`](references/dependency-selection-guide.md)**
128
129Deciding whether to add a new dependency and choosing between similar packages.
130
131- Minimal dependencies principle (best dependency is the one you don't add)
132- Evaluation checklist (maintenance, bundle size, security, alternatives)
133- Choosing between similar packages (comparison matrix)
134- When to reject a dependency
135
136### Update Strategies
137
138**[`references/update-strategies.md`](references/update-strategies.md)**
139
140Keeping dependencies up to date safely while minimizing breaking changes and security risks.
141
142- Update strategies (continuous, scheduled, security-only)
143- Safe update workflow (check outdated, categorize risk, test, deploy)
144- Automated update tools (Dependabot, Renovate, npm-check-updates)
145- Handling breaking changes and rollback plans
146
147### Monorepo Management
148
149**[`references/monorepo-patterns.md`](references/monorepo-patterns.md)**
150
151Managing multiple related packages in a single repository with shared dependencies.
152
153- Workspace tools (pnpm, npm, yarn workspaces)
154- Monorepo structure and organization
155- Build optimization (Nx, Turborepo)
156- Versioning and publishing strategies
157
158### Transitive Dependencies
159
160**[`references/transitive-dependencies.md`](references/transitive-dependencies.md)**
161
162Dealing with dependencies of your dependencies (indirect dependencies).
163
164- Viewing dependency trees (npm ls, pnpm why, pipdeptree)
165- Resolving transitive conflicts (overrides, resolutions, constraints)
166- Security risks and version conflicts
167- Best practices (use sparingly, document, test)
168
169### Ecosystem-Specific Guides
170
171**[`references/ecosystem-guides.md`](references/ecosystem-guides.md)**
172
173Language and package-manager-specific best practices.
174
175- Node.js (npm, yarn, pnpm comparison and best practices)
176- Python (pip, poetry, conda)
177- Rust (cargo), Go (go mod), Java (maven, gradle)
178- PHP (composer), .NET (nuget)
179
180### Anti-Patterns
181
182**[`references/anti-patterns.md`](references/anti-patterns.md)**
183
184Common mistakes to avoid when managing dependencies.
185
186- Critical anti-patterns (not committing lockfiles, wildcards, ignoring audits)
187- Dangerous anti-patterns (never updating, deprecated packages)
188- Moderate anti-patterns (overusing overrides, ignoring peer deps)
189
190---
191
192## Navigation: Templates
193
194### Node.js
195
196**[`assets/nodejs/`](assets/nodejs/)**
197
198- [`package-json-template.json`](assets/nodejs/package-json-template.json) - Production-ready package.json with best practices
199- `npmrc-template.txt` - Team configuration for npm
200- [`pnpm-workspace-template.yaml`](assets/nodejs/pnpm-workspace-template.yaml) - Monorepo workspace setup
201
202### Python
203
204**[`assets/python/`](assets/python/)**
205
206- [`pyproject-toml-template.toml`](assets/python/pyproject-toml-template.toml) - Poetry configuration with best practices
207
208### Automation
209
210**[`assets/automation/`](assets/automation/)**
211
212- [`dependabot-config.yml`](assets/automation/dependabot-config.yml) - GitHub Dependabot configuration
213- [`renovate-config.json`](assets/automation/renovate-config.json) - Renovate Bot configuration
214- [`audit-checklist.md`](assets/automation/audit-checklist.md) - Security audit workflow
215- **[`template-supply-chain-security.md`](assets/automation/template-supply-chain-security.md)** - **NEW** SBOM, provenance, vulnerability management
216- [`template-dependency-upgrade-playbook.md`](assets/automation/template-dependency-upgrade-playbook.md) - Upgrade batching, rollout, rollback
217- [`template-sbom-vuln-triage-checklist.md`](assets/automation/template-sbom-vuln-triage-checklist.md) - SBOM mapping + vulnerability triage
218
219---
220
221## Supply Chain Security
222
223**[assets/automation/template-supply-chain-security.md](assets/automation/template-supply-chain-security.md)** — Production-grade dependency security.
224
225Related templates:
226- [assets/automation/template-dependency-upgrade-playbook.md](assets/automation/template-dependency-upgrade-playbook.md)
227- [assets/automation/template-sbom-vuln-triage-checklist.md](assets/automation/template-sbom-vuln-triage-checklist.md)
228
229### Key Sections
230
231- **SBOM Generation** — CycloneDX, SPDX formats; CI/CD integration
232- **AI BOM (Emerging)** — Extended SBOM for AI-native systems (models, datasets, training artifacts)
233- **Provenance & Attestation** — SLSA levels, Sigstore signing, npm provenance
234- **Vulnerability Management** — Triage workflow, severity SLAs, scanning tools
235- **Upgrade Playbooks** — Batching strategy, rollback procedures
236- **Pinning & Reproducibility** — Lockfiles, hash pinning, version constraints
237- **EU Cyber Resilience Act** — SBOM requirements effective Dec 2027
238
239### Do / Avoid
240
241#### GOOD: Do
242
243- Generate SBOM for every release
244- Sign release artifacts (Sigstore/cosign)
245- Run vulnerability scans in CI/CD
246- Fix critical vulnerabilities within 24 hours
247- Use lockfiles for reproducible builds
248- Verify npm package provenance
249- Batch non-security updates by risk level
250
251#### BAD: Avoid
252
253- Publishing without SBOM
254- Using unsigned packages in production
255- Ignoring vulnerability scanner output
256- Updating all dependencies at once
257- Using wildcard version ranges (`*`, `>=`)
258- Committing without updating lockfile
259- Bypassing security gates "just this once"
260
261### Anti-Patterns
262
263| Anti-Pattern | Problem | Fix |
264|--------------|---------|-----|
265| **No SBOM** | Can't respond to supply chain attacks | Generate SBOM in CI/CD |
266| **Unsigned artifacts** | Tampering undetectable | Sign with Sigstore |
267| **Floating versions** | Build not reproducible | Use lockfiles + exact versions |
268| **All-at-once updates** | Hard to bisect regressions | Batch by risk level |
269| **npm install in CI** | Non-deterministic | Use `npm ci` |
270| **No audit gate** | Vulnerabilities ship to prod | Gate deployments on audit |
271
272---
273
274## AI-Generated Dependency Risks
275
276> **WARNING**: AI coding agents can introduce vulnerable or non-existent packages at scale (Endor Labs, 2025).
277
278### The Problem
279
280AI tools accelerate coding but introduce supply chain risks:
281
282- **Hallucinated packages** — AI suggests packages that don't exist (typosquatting vectors)
283- **Vulnerable dependencies** — AI recommends outdated or CVE-affected versions
284- **Unnecessary dependencies** — AI over-relies on packages for simple tasks
285
286### Best Practices
287
288| Do | Don't |
289| --- | --- |
290| Treat AI-generated code as untrusted third-party input | Blindly accept AI dependency suggestions |
291| Enforce same SAST/SCA scanning for AI-generated code | Skip security review for "AI-written" code |
292| Verify all AI-suggested packages actually exist | Trust AI to know current package versions |
293| Integrate security tools into AI workflows (MCP) | Allow AI to add dependencies without review |
294| Vet MCP servers as part of supply chain | Use unvetted AI integrations |
295
296### Validation Checklist
297
298Before accepting AI-suggested dependencies:
299
300- [ ] Package exists on registry (npm, PyPI, crates.io)
301- [ ] Package name is spelled correctly (no typosquatting)
302- [ ] Version is current and maintained
303- [ ] `npm audit` / `pip-audit` shows no vulnerabilities
304- [ ] Weekly downloads >1000 (established package)
305- [ ] Last commit <6 months (actively maintained)
306
307---
308
309## Optional: AI/Automation
310
311> **Note**: AI assists with triage but security decisions need human judgment.
312
313- **Automated PR triage** — Categorize dependency updates by risk
314- **Changelog summarization** — Summarize breaking changes in updates
315- **Vulnerability correlation** — Link CVEs to affected packages
316
317### Bounded Claims
318
319- AI cannot determine business risk acceptance
320- Automated fixes require security team review
321- Vulnerability severity context needs human validation
322
323---
324
325## Quick Decision Matrix
326
327| Scenario | Recommendation |
328|----------|----------------|
329| Adding new dependency | Check Bundlephobia, npm audit, weekly downloads, last commit |
330| Updating dependencies | Use `npm outdated`, update in batches, test in staging |
331| Security vulnerability found | Use `npm audit fix`, review CHANGELOG, test, deploy immediately |
332| Monorepo setup | Use **pnpm workspaces** or Nx/Turborepo for build caching |
333| Transitive conflict | Use `overrides` sparingly, document why, test thoroughly |
334| Choosing JS package manager | **pnpm** (fastest, disk-efficient), **Bun** (7× faster), npm (most compatible) |
335| Python environment | **uv** (10-100× faster), Poetry (mature), pip+venv (simple), conda (data science) |
336
337---
338
339## Core Principles
340
341### 1. Always Commit Lockfiles
342
343Lockfiles ensure reproducible builds across environments. Never add them to `.gitignore`.
344
345**Exception**: Don't commit `Cargo.lock` for Rust libraries (only for applications).
346
347### 2. Use Semantic Versioning
348
349Use caret (`^`) for most dependencies, exact versions for mission-critical, avoid wildcards (`*`).
350
351```json
352{
353 "dependencies": {
354 "express": "^4.18.0", // Allows patches and minors
355 "critical-lib": "1.2.3" // Exact for critical
356 }
357}
358```
359
360### 3. Audit Dependencies Regularly
361
362Run security audits weekly, fix critical vulnerabilities immediately.
363
364```bash
365npm audit
366npm audit fix
367```
368
369### 4. Minimize Dependencies
370
371The best dependency is the one you don't add. Ask: Can I implement this in <100 LOC?
372
373### 5. Update Regularly
374
375Update monthly or quarterly. Don't let technical debt accumulate.
376
377```bash
378npm outdated
379npm update
380```
381
382### 6. Use Overrides Sparingly
383
384Only override transitive dependencies for security patches or conflicts. Document why.
385
386```json
387{
388 "overrides": {
389 "axios": "1.6.0" // CVE-2023-xxxxx fix
390 }
391}
392```
393
394---
395
396## Related Skills
397
398For complementary workflows and deeper dives:
399
400- [`dev-api-design`](../dev-api-design/SKILL.md) - API versioning strategies, dependency injection patterns
401- [`git-workflow`](../git-workflow/SKILL.md) - Git workflows for managing lockfile conflicts, branching strategies
402- [`qa-testing-strategy`](../qa-testing-strategy/SKILL.md) - Testing strategies for dependency updates, integration testing
403- [`software-security-appsec`](../software-security-appsec/SKILL.md) - OWASP Top 10, cryptography standards, authentication patterns
404- [`ops-devops-platform`](../ops-devops-platform/SKILL.md) - CI/CD pipelines, Docker containerization, DevSecOps, deployment automation
405- [`docs-codebase`](../docs-codebase/SKILL.md) - Documenting dependency choices, ADRs, changelogs
406
407---
408
409## External Resources
410
411See [`data/sources.json`](data/sources.json) for curated resources:
412
413- **Package managers**: npm, pnpm, Yarn, pip, Poetry, Cargo, Go modules, Maven, Composer
414- **Semantic versioning**: SemVer spec, version calculators, constraint references
415- **Security tools**: Snyk, Dependabot, GitHub Advanced Security, OWASP Dependency-Check, pip-audit, cargo-audit, Socket.dev, Renovate
416- **Lockfile management**: Official docs for package-lock.json, poetry.lock, Cargo.lock, pnpm-lock.yaml
417- **Monorepo tools**: pnpm workspaces, npm workspaces, Yarn workspaces, Nx, Turborepo, Lerna, Bazel
418- **Analysis tools**: Bundlephobia, npm-check-updates, depcheck, pipdeptree, cargo tree
419- **Supply chain security**: SLSA framework, SBOM (CISA), Sigstore, npm provenance, OpenSSF Scorecard
420- **Best practices**: npm/Poetry/Cargo guides, ACM Queue articles, dependency hell references
421- **Version management**: nvm, pyenv, rustup, asdf
422- **Learning resources**: npm guides, Python Packaging User Guide, Rust Book, Monorepo.tools
423
424---
425
426## Usage Notes
427
428**For Codex / Claude Code:**
429
430- Use this skill when users need dependency management guidance
431- Reference specific resources based on the task (lockfiles, security, updates)
432- Provide ecosystem-specific guidance (Node.js, Python, Rust)
433- Always recommend security audits and reproducible builds
434- Encourage minimal dependencies and regular updates
435- Link to templates for common configurations
436
437**Best Practices:**
438
439- Always commit lockfiles (except Cargo.lock for libraries)
440- Use semantic versioning (caret for most deps, exact for critical)
441- Audit dependencies weekly (`npm audit`, `pip-audit`, `cargo audit`)
442- Update dependencies monthly or quarterly (not all at once)
443- Choose package manager based on project needs (pnpm for speed, Poetry for Python apps)
444- Document dependency choices in ADRs (Architecture Decision Records)
445
446---
447
448> **Success Criteria:** Dependencies are minimal, well-maintained, secure, reproducible across environments, and regularly audited for vulnerabilities.
449
450---
451
452## Trend Awareness Protocol
453
454**IMPORTANT**: When users ask recommendation questions about package managers, dependency tools, or supply chain security, you MUST use WebSearch to check current trends before answering.
455
456### Trigger Conditions
457
458- "What's the best package manager for [ecosystem]?"
459- "What should I use for [dependency management/security]?"
460- "What's the latest in dependency management?"
461- "Current best practices for [npm/pnpm/Poetry]?"
462- "Is [tool/approach] still relevant in 2026?"
463- "[pnpm] vs [npm] vs [yarn]?"
464- "Best dependency security scanner?"
465
466### Required Searches
467
4681. Search: `"dependency management best practices 2026"`
4692. Search: `"[specific tool] vs alternatives 2026"`
4703. Search: `"supply chain security trends January 2026"`
4714. Search: `"[package manager] features 2026"`
472
473### What to Report
474
475After searching, provide:
476
477- **Current landscape**: What dependency tools are popular NOW
478- **Emerging trends**: New package managers, security tools, or patterns gaining traction
479- **Deprecated/declining**: Tools/approaches losing relevance or support
480- **Recommendation**: Based on fresh data, not just static knowledge
481
482### Example Topics (verify with fresh search)
483
484- Package managers (pnpm, npm, yarn, Poetry, uv for Python)
485- Security scanning (Snyk, Dependabot, Socket.dev)
486- Supply chain security (SBOM, Sigstore, SLSA)
487- Monorepo tools (Nx, Turborepo, Bazel)
488- Lockfile and reproducibility patterns
489- Automated dependency updates (Renovate, Dependabot)