Agent Skillsbacknotprop/plannotator › review-renovate

review-renovate

GitHub

审核 Renovate 提交的 GitHub Actions 依赖更新 PR,验证供应链完整性(SHA 与标签匹配),检查变更日志中的破坏性更改及工作流兼容性,确保 CI/CD 安全升级。

.agents/skills/review-renovate/SKILL.md backnotprop/plannotator

Trigger Scenarios

收到 Renovate bot 的 GitHub Actions 依赖更新 PR 需要验证第三方 GitHub Action 版本升级的安全性

Install

npx skills add backnotprop/plannotator --skill review-renovate -g -y
More Options

Non-standard path

npx skills add https://github.com/backnotprop/plannotator/tree/main/.agents/skills/review-renovate -g -y

Use without installing

npx skills use backnotprop/plannotator@review-renovate

指定 Agent (Claude Code)

npx skills add backnotprop/plannotator --skill review-renovate -a claude-code -g -y

安装 repo 全部 skill

npx skills add backnotprop/plannotator --all -g -y

预览 repo 内 skill

npx skills add backnotprop/plannotator --list

SKILL.md

Frontmatter
{
    "name": "review-renovate",
    "description": "Review Renovate bot PRs that update GitHub Actions dependencies. Verifies supply chain integrity by checking pinned commit SHAs against upstream tagged releases, reviews changelogs for breaking changes, and confirms compatibility with existing workflow configurations. Use when a Renovate PR updates GitHub Actions in .github\/workflows\/."
}

Review Renovate GitHub Actions PRs

You are reviewing a Renovate bot PR that updates GitHub Actions dependencies. Your job is to verify supply chain integrity and ensure the upgrades won't break CI/CD workflows.

Inputs

You will be given a PR number or URL. Use gh CLI to fetch PR details and diff.

Steps

1. Fetch PR metadata and diff

gh pr view <PR> --json title,body,files,commits,author,headRefName
gh pr diff <PR>

Confirm the PR author is app/renovate. If not, flag this immediately — it may not be an automated dependency update.

2. Identify all action version changes

From the diff, extract each changed action:

  • Full action name (e.g., oven-sh/setup-bun)
  • Old version tag and pinned SHA
  • New version tag and pinned SHA
  • Update type (patch, minor, major)

3. Verify pinned SHAs against upstream tags

For every action being updated, verify both old and new SHAs match the claimed version tags:

gh api repos/{owner}/{repo}/git/ref/tags/{version} --jq '.object.sha'

Compare each result against the SHA in the workflow file. If any SHA does not match, stop and report a supply chain integrity failure. Do not approve the PR.

4. Review changelogs for breaking changes

From the PR body (Renovate includes release notes), check each updated action for:

  • Removed inputs or outputs that the workflows currently use
  • Changed default behavior for inputs the workflows rely on
  • New required inputs
  • Major version bumps (these almost always have breaking changes)

5. Check workflow compatibility

Read the affected workflow files and verify:

  • No removed or renamed inputs are being used
  • No changed defaults affect current behavior
  • The action's runtime requirements are still met (e.g., Node.js version compatibility)

6. Report findings

Present a summary table:

Action Old New Type SHA verified
... ... ... patch/minor/major yes/NO

Then state:

  • Whether all SHAs are verified
  • Whether any breaking changes were found
  • Whether the workflows remain compatible
  • A clear safe to merge or do not merge recommendation

Version History

  • 2ca55c8 Current 2026-08-20 12:32

Same Skill Collection

.agents/skills/pierre-guard/SKILL.md
.agents/skills/release/SKILL.md
.agents/skills/update-deps/SKILL.md
apps/kiro-cli/skills/plannotator-annotate/SKILL.md
apps/skills/claude/plannotator-annotate/SKILL.md
apps/skills/claude/plannotator-last/SKILL.md
apps/skills/claude/plannotator-review/SKILL.md
apps/skills/core/plannotator-annotate/SKILL.md
apps/skills/core/plannotator-last/SKILL.md
apps/skills/core/plannotator-review/SKILL.md
apps/skills/core/plannotator/SKILL.md
apps/skills/extra/plannotator-compound/SKILL.md
apps/skills/extra/plannotator-setup-goal/SKILL.md
apps/skills/extra/plannotator-visual-explainer/SKILL.md
apps/kiro-cli/skills/plannotator-review/SKILL.md

Metadata

Files
0
Version
9e3af49
Hash
2c3a0b92
Indexed
2026-08-20 12:32

Accueil - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-09-06 18:31
浙ICP备14020137号-1 $Carte des visiteurs$