返回顶部
d

deps-mgmt

Deep dependency management workflow—inventory, upgrade policy, security patches, licensing, lockfiles, and supply-chain hygiene. Use when upgrading frameworks, resolving CVEs, or standardizing how teams pin dependencies.

作者: admin | 来源: ClawHub
源自
ClawHub
版本
V 1.0.0
安全检测
已通过
80
下载量
0
收藏
概述
安装方式
版本历史

deps-mgmt

# Dependencies Dependencies are **supply-chain** surface area: versions affect security, reproducibility, and upgrade cost. ## When to Offer This Workflow **Trigger conditions:** - Dependabot noise; major version upgrades - CVE response or license audit - “Works on my machine” due to unpinned dependencies **Initial offer:** Use **six stages**: (1) inventory & risk, (2) policy & cadence, (3) lockfiles & reproducibility, (4) upgrades & testing, (5) security & licensing, (6) governance & tooling). Confirm ecosystem (npm, pip, Maven, Go modules, etc.). --- ## Stage 1: Inventory & Risk **Goal:** Direct vs transitive dependencies; flag critical packages (crypto, auth, parsing, serialization). **Exit condition:** SBOM or export for top applications; list of critical deps. --- ## Stage 2: Policy & Cadence **Goal:** When to upgrade (time-based vs on-demand); SemVer rules for libraries vs applications. --- ## Stage 3: Lockfiles & Reproducibility **Goal:** Committed lockfiles for deployable apps; libraries test against a compatibility matrix instead of one frozen lock. --- ## Stage 4: Upgrades & Testing **Goal:** Prefer one major bump per PR when feasible; CI matrix on supported language/runtime versions. --- ## Stage 5: Security & Licensing **Goal:** SCA scanning; patch SLA by severity; license allowlist for compliance. --- ## Stage 6: Governance & Tooling **Goal:** Renovate/Bot policies; pin internal packages; document exceptions and overrides. --- ## Final Review Checklist - [ ] Inventory and risk hotspots known - [ ] Upgrade cadence and semver policy documented - [ ] Lockfiles or matrix strategy per repo type - [ ] CI validates upgrades - [ ] SCA and license policy enforced ## Tips for Effective Guidance - Transitive CVEs may need overrides—trace the dependency graph. - Pin CI images and toolchains, not only application dependencies. ## Handling Deviations - Monorepos: shared versions with Nx/Bazel/etc.—coordinate breaking upgrades.

标签

skill ai

通过对话安装

该技能支持在以下平台通过对话安装:

OpenClaw WorkBuddy QClaw Kimi Claude

方式一:安装 SkillHub 和技能

帮我安装 SkillHub 和 deps-mgmt-1775984047 技能

方式二:设置 SkillHub 为优先技能安装源

设置 SkillHub 为我的优先技能安装源,然后帮我安装 deps-mgmt-1775984047 技能

通过命令行安装

skillhub install deps-mgmt-1775984047

下载 Zip 包

⬇ 下载 deps-mgmt v1.0.0

文件大小: 1.7 KB | 发布时间: 2026-4-13 10:01

v1.0.0 最新 2026-4-13 10:01
Initial release of the deps-mgmt skill providing a structured workflow for deep dependency management.

- Introduces a six-stage process covering inventory, policy, reproducibility, upgrades, security, and governance.
- Includes clear trigger conditions to identify when to apply the workflow.
- Offers defined goals and exit conditions for each workflow stage.
- Provides a comprehensive final review checklist to ensure best practices.
- Shares tips for effective dependency management and strategies for handling monorepo deviations.

Archiver·手机版·闲社网·闲社论坛·羊毛社区· 多链控股集团有限公司 · 苏ICP备2025199260号-1

Powered by Discuz! X5.0   © 2024-2025 闲社网·线报更新论坛·羊毛分享社区·http://xianshe.com

p2p_official_large
返回顶部