跳转到主要内容
此内容尚未提供您的语言版本,正在以英文显示。

Dependency Management

技能 已验证 活跃

Manage third-party libraries, runtimes, and SaaS dependencies. Use this skill when setting an update cadence, responding to security advisories, dealing with deprecated dependencies, evaluating new dependencies, auditing what's installed, or unblocking a dependency upgrade. Triggers on dependency, package update, security patch, lockfile, deprecated, breaking change, supply chain, dependency audit, npm audit, dependabot, renovate. Also triggers when a build breaks after an update or when an advisory is published for a used package.

目的

To help developers and teams establish and maintain robust dependency management practices, ensuring security, currency, and stability across their projects.

功能

  • Dependency inventory and categorization
  • Security advisory auditing and prioritization
  • Major version upgrade planning and execution
  • Policy setting for updates, security, and pinning
  • Automation recommendations for updates and audits

使用场景

  • Setting up dependency hygiene for new or existing projects
  • Responding to security advisories and vulnerability reports
  • Planning and executing major version upgrades
  • Evaluating and onboarding new dependencies
  • Auditing installed dependencies and their usage

非目标

  • General code review
  • Infrastructure vulnerability scanning
  • Pinning vendor or service contracts
  • Performance impact analysis of dependencies

安装

npx skills add rampstackco/claude-skills

通过 npx 运行 Vercel skills CLI(skills.sh)— 需要本地安装 Node.js,以及至少一个兼容 skills 的智能体(Claude Code、Cursor、Codex 等)。前提是仓库遵循 agentskills.io 格式。

质量评分

已验证
98 /100
1 day ago 分析

信任信号

最近提交4 days ago
星标168
许可证MIT
状态
查看源代码