# Sq Gomod Dependabot

> Reviews and merges Dependabot pull requests for Go modules (gomod) at the sq repo root. Use for dependabot gomod PRs, go.mod/go.sum updates, and Go module security bumps—not site/ Bun PRs.

- Skill: `neilotoole/sq-gomod-dependabot` (Agent Skill)
- Install (CLI): `npx skillmds@latest add neilotoole/sq-gomod-dependabot`
- Raw SKILL.md: https://api.skillmd.com/api/skills/neilotoole/sq-gomod-dependabot/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- License: MIT
- Author: neilotoole (https://skillmd.com/u/neilotoole)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/neilotoole/sq-gomod-dependabot

---


# sq-gomod-dependabot

Maintainer workflow for Dependabot PRs updating [`go.mod`](../../../go.mod) /
[`go.sum`](../../../go.sum) at the repository root. For [`site/`](../../../site/)
Bun/Hugo PRs, use [`sq-site-dependabot`](../sq-site-dependabot/SKILL.md); for
GitHub Actions pins under `.github/workflows/`, use
[`sq-actions-dependabot`](../sq-actions-dependabot/SKILL.md).

No `bun.lock` sequencing — multiple gomod PRs are less coupled than site PRs,
but still prefer merging after CI is green.

## Operating modes

| Mode         | Actions                           | Merge  |
| ------------ | --------------------------------- | ------ |
| **Audit**    | List/classify; direct vs indirect | No     |
| **Validate** | Diff review; `make test-short`    | No     |
| **Full**     | Validate + merge with consent     | Per PR |

Default to **Audit** unless the user asks to merge.

## Phase 0 — Tool bootstrap

```bash
command -v gh >/dev/null && gh auth status
command -v go >/dev/null && go version
```

## Phase 1 — Discovery

From repository root:

```bash
gh pr list --author 'app/dependabot' --state open \
  --json number,title,headRefName,mergeable,statusCheckRollup \
  --jq '.[] | select(.headRefName | test("^dependabot/")) | select(.title | test("go|gomod|golang"; "i"))'
```

The title filter matches `go`/`golang`, so it also catches GitHub Actions PRs
like `goreleaser-action` or `golangci-lint-action`. Those touch only
`.github/workflows/`, not `go.mod`; hand them to
[`sq-actions-dependabot`](../sq-actions-dependabot/SKILL.md). Confirm the PR does
**not** only touch `site/` (`gh pr diff <n> --name-only`); if it touches both,
split judgment: site hunks → `sq-site-dependabot`.

## Phase 2 — Risk

| Level  | Examples                          | Action             |
| ------ | --------------------------------- | ------------------ |
| Low    | Patch indirect, test-only modules | Merge after CI     |
| Medium | Direct minor/patch runtime dep    | Notes + test-short |
| High   | Major, `replace`, breaking sec    | Hold; full review  |

## Phase 3 — Validate

On PR branch:

```bash
make test-short
# or make test for full driver integration (Docker)
```

Review `go mod why` / diff for unexpected indirect churn.

## Phase 4 — Merge (consent-gated)

After required checks pass:

```bash
gh pr merge <n> --squash --delete-branch
```

Use `--admin` only when the user explicitly requests and checks are green.

## Verdict template

```markdown
## Dependabot gomod PR #NNN — <module>

- **Direct/indirect:** …
- **CI:** pass / fail
- **make test-short:** pass / fail
- **Verdict:** merge | hold
```

See [AGENTS.md](../../../AGENTS.md#agent-skills-contributors).

