dependabot-triage
Triage JavaScript dependency alerts with exposure and lockfile checks
Triage JavaScript dependency alerts with exposure and lockfile checks
dependabot-triage handles npm, pnpm, yarn, and bun alerts by ranking impact, exposure, and CVSS, mapping import sites, selecting a minimal patched version, and checking the changelog for breaking changes. It updates every package-manager override in play, regenerates lockfiles, and aborts when resolved versions drift across local and CI tooling. The skill pauses for explicit approval before applying a bump or opening a pull request.
Resource types
Use cases
Platforms
Public GitHub facts last synced Jul 10, 2026.
Audit suspension risks in a Claude Code working environment.
Check whether a specific CVE actually applies to your environment.
Store and inject development secrets through 1Password from Claude Code.
Audit a deployed public app for production gaps missed during coding.