xiaohongshu
xiaohongshu
checking-dependabot-prs
DependabotのPRをレビューの必要度の観点で検証する。「DependabotのPRを確認して」「Dependabotの更新は安全?」などの依頼時に使用する。
Full skill instructions
指定リポジトリのDependabot PRについてセキュリティ検証を行う。
Progress:
- [ ] Step 1: PR一覧を取得
- [ ] Step 2: セキュリティ面を確認
- [ ] Step 3: 破壊的変更を確認
- [ ] Step 4: 結果を報告
gh pr list --state open --repo OWNER/REPO --author "dependabot[bot]" --json number,title,url,createdAt
DependabotのPRが10件を超える場合はユーザーに確認件数を尋ねる。
以下の方法で更新対象パッケージの脆弱性を確認する:
curl -s -H "Content-Type: application/json" https://api.osv.dev/v1/query -d QUERY
OSVのQUERY例(エコシステムとパッケージ名を明示する):
curl -s -H "Content-Type: application/json" https://api.osv.dev/v1/query -d '{
"package": {
"name": "PACKAGE_NAME",
"ecosystem": "ECOSYSTEM"
},
"version": "X.Y.Z"
}'
エコシステムが不明な場合はユーザーに確認する。
PRタイトルからバージョン番号を抽出し、セマンティックバージョニングに基づいて判断:
gh pr view PR_NUMBER --repo OWNER/REPO --json body
Dependabotが生成するPR本文には以下の情報が含まれる:
PR本文を読み込んで破壊的変更が加えられていないかどうか確認する。
メジャーバージョンアップの場合、実際の変更内容を確認:
gh pr diff PR_NUMBER --repo OWNER/REPO
requirements.txt や pyproject.toml などの依存関係ファイルの変更を確認し、他のパッケージへの影響を評価する。
以下のテンプレートで報告する:
## Dependabot PR セキュリティレビュー結果
**リポジトリ:** OWNER/REPO
**確認日:** YYYY-MM-DD
**確認件数:** N件
### サマリ
- ✅ 承認推奨: N件
- ⚠️ 要確認: N件
- ❌ 非推奨: N件
### 各PRの詳細
#### パッケージ名 vX.X.X → vY.Y.Y
- **PR:** https://github.com/...
- **脆弱性チェック:** ✅ 既知の脆弱性なし (OSV: [ID/URL])
- **破壊的変更チェック:** ✅ 破壊的変更なし
- **補足:** エコシステム/影響範囲/判断根拠を簡潔に記載
- **判定:** ✅ 承認推奨
xiaohongshu
technical spec
product ux expert
database patterns
Conduct multi-agent task orchestration and workflow coordination.
Initialize project with Conductor artifacts (product definition,
Expert in web animations, transitions, and motion design using Framer Motion and CSS
Creates Mermaid and ASCII diagrams for flowcharts, architecture, ERDs, state machines, mindmaps, and more. Use when user mentions diagram, flowchart, mermaid, ASCII diagram, text diagram, terminal diagram, visualize, C4, mindmap, architecture diagram, sequence diagram, ERD, or needs visual docume...
PostgreSQL bindings for H3 hexagonal grid system. Use when working with H3 cells in Postgres, including spatial indexing, geometry/geography integration, and raster analysis.
Context-Driven Development skill for projects using Conductor. Use this skill when you detect a `conductor/` directory in the project, when working on tasks defined in a `plan.md` file, or when the user asks about tracks, specs, or plans. Automatically applies TDD workflow, tracks task completion...
Display project status, active tracks, and next actions
Official Stakpak application containerization standard operating procedure, a step-by-step guidline to properly dockerize applications. This is a rule book curated by the Stakpak Team.
Generate, edit, and beat-sync AI video with leading models in one workspace.
The world's fastest calendar for remote work
Transform Your Design with AI Designer by ImgCreator.ai
Revolutionizing Video Production with AI-Powered Creativity
Extend an image past the frame and let AI fill the new aspect ratio.
Discover your celebrity doppelgänger with StarByFace!
ChainClarity explains 700+ crypto whitepapers in plain English, with layered summaries, comparisons, research tools, alerts, and a $4.99 Pro plan.
Opus.ai: Revolutionize Your Web Experience