Agent Skillscosmicstack-labs/mercury-agent-skills › dependency-management

dependency-management

GitHub

提供依赖管理最佳实践,涵盖版本锁定策略、漏洞扫描工具与流程、Monorepo模式及升级工作流,旨在规模化安全地管理项目依赖。

categories/development/dependency-management/SKILL.md cosmicstack-labs/mercury-agent-skills

Trigger Scenarios

需要制定或优化依赖版本策略 执行依赖漏洞扫描与安全审计 处理Monorepo依赖冲突与去重 规划依赖升级与发布流程

Install

npx skills add cosmicstack-labs/mercury-agent-skills --skill dependency-management -g -y
More Options

Non-standard path

npx skills add https://github.com/cosmicstack-labs/mercury-agent-skills/tree/main/categories/development/dependency-management -g -y

Use without installing

npx skills use cosmicstack-labs/mercury-agent-skills@dependency-management

指定 Agent (Claude Code)

npx skills add cosmicstack-labs/mercury-agent-skills --skill dependency-management -a claude-code -g -y

安装 repo 全部 skill

npx skills add cosmicstack-labs/mercury-agent-skills --all -g -y

预览 repo 内 skill

npx skills add cosmicstack-labs/mercury-agent-skills --list

SKILL.md

Frontmatter
{
    "name": "dependency-management",
    "metadata": {
        "tags": [
            "dependencies",
            "package-management",
            "security",
            "monorepo",
            "upgrades"
        ],
        "author": "cosmicstack-labs",
        "version": "1.0.0",
        "category": "development"
    },
    "description": "Version pinning, vulnerability scanning, monorepo patterns, and upgrade workflows"
}

Dependency Management

Safely manage project dependencies at scale.

Version Strategy

Pinning Approaches

Strategy Format Risk Best For
Exact 1.2.3 Low Docker, CI, production
Caret ^1.2.3 Medium Libraries, apps with good tests
Tilde ~1.2.3 Low-Medium Conservative updates
Range >=1.2.3 <2.0.0 High Rare, legacy
Floating * Very High Never in production

Rule: Pin exact versions for production, caret for libraries.

Vulnerability Scanning

Tools

  • npm audit / yarn audit — quick JS check
  • Dependabot — GitHub-native, auto PRs
  • Snyk — deeper scanning, prioritization
  • Trivy — container scanning
  • OWASP Dependency-Check — Java/.NET

Workflow

  1. Scan on every PR (fail on critical/high)
  2. Weekly full scan of all repos
  3. Patch critical (<7 days), high (<30 days)
  4. Track CVEs by severity in dashboard
  5. SBOM generation per release

Monorepo Patterns

  • Use workspaces (npm/yarn/pnpm workspaces)
  • Shared dependency versions (single source of truth)
  • Independent vs locked version strategy
  • Deduplicate (npx dedupe after major changes)
  • Audit tree to find conflicting transitive deps

Upgrade Workflow

  1. Check changelog for breaking changes
  2. Run tests (you have tests, right?)
  3. Upgrade one major version at a time
  4. Run full test suite + build
  5. Deploy to staging, verify
  6. Monitor for regressions (logs, metrics, errors)

Version History

  • 38e2523 Current 2026-07-05 19:38

Same Skill Collection

categories/ai-ml/agent-audit-logging/SKILL.md
categories/ai-ml/agent-handoff-protocols/SKILL.md
categories/ai-ml/agent-health-monitoring/SKILL.md
categories/ai-ml/agent-task-delegation/SKILL.md
categories/ai-ml/ai-agent-design/SKILL.md
categories/ai-ml/error-recovery-retry/SKILL.md
categories/ai-ml/memory-management/SKILL.md
categories/ai-ml/prompt-engineering/SKILL.md
categories/ai-ml/prompt-version-management/SKILL.md
categories/ai-ml/routerbase-model-gateway/SKILL.md
categories/ai-ml/token-budget-tracking/SKILL.md
categories/automation/daily-briefing/SKILL.md
categories/automation/screenshot/SKILL.md
categories/automation/shell-scripting/SKILL.md
categories/automation/twitter-account-manager/SKILL.md
categories/automation/workflow-automation/SKILL.md
categories/automation/x-twitter-automation/SKILL.md
categories/backend/api-design/SKILL.md
categories/backend/authentication-authorization/SKILL.md
categories/backend/caching-strategies/SKILL.md
categories/backend/database-design/SKILL.md
categories/backend/message-queues/SKILL.md
categories/backend/microservices/SKILL.md
categories/backend/nodejs-patterns/SKILL.md
categories/backend/python-patterns/SKILL.md
categories/backend/serverless-patterns/SKILL.md
categories/business/event-staffing-compliance/SKILL.md
categories/business/event-staffing-ordering/SKILL.md
categories/business/negotiation/SKILL.md
categories/business/startup-strategy/SKILL.md
categories/career/career-planning/SKILL.md
categories/career/interview-prep/SKILL.md
categories/career/linkedin-optimization/SKILL.md
categories/career/resume-writing/SKILL.md
categories/career/salary-negotiation/SKILL.md
categories/creative-personal-development/content-repurposer/SKILL.md
categories/creative-personal-development/daily-standup-journal/SKILL.md
categories/creative-personal-development/decision-matrix/SKILL.md
categories/creative-personal-development/idea-validator/SKILL.md
categories/creative-personal-development/meeting-note-summarizer/SKILL.md
categories/creative-personal-development/personal-branding-statement/SKILL.md
categories/creative-personal-development/storytelling-advisor/SKILL.md
categories/creative-personal-development/time-blocking-scheduler/SKILL.md
categories/data/data-pipeline/SKILL.md
categories/design/accessibility/SKILL.md
categories/design/ui-design-system/SKILL.md
categories/development/api-documentation/SKILL.md
categories/development/architecture-decision-records/SKILL.md
categories/development/clean-code/SKILL.md
categories/development/code-review/SKILL.md

Metadata

Files
0
Version
4c57cf2
Hash
f02780d8
Indexed
2026-07-05 19:38

trang chủ - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-07 07:59
浙ICP备14020137号-1 $bản đồ khách truy cập$