Dependabot Audit

Audit an automated dependency-bump PR and produce an evidence-backed merge recommendation — verify lockfile artifact hashes against the registry, cross-check the true latest version, read changelogs for security and behavior changes, reproduce the repo's own checks in an isolated worktree, and report. Verifies uv.lock, GitHub Actions and pre-commit hooks end to end; any other ecosystem gets the ecosystem-independent phases and a stated boundary rather than an improvised recipe. Use when the user asks to review, audit, check, or decide on a Dependabot or Renovate PR, a dependency bump, a lockfile PR, or asks "is this safe to merge".

Machai-Kydoimos Updated

File contents

Machai-Kydoimos/dependabot-audit/tree/main/skills/dependabot-audit commit 29988b1320

Frequently asked questions

npx skillmds@latest add machai-kydoimos/dependabot-audit