MCP HubMCP Hub
스킬 목록으로 돌아가기

update-deps

backnotprop
업데이트됨 2 days ago
1 조회
5,598
382
5,598
GitHub에서 보기
기타ai

정보

이 스킬은 변경 사항을 적용하기 전에 npm/Bun 의존성을 공급망 무결성 검사와 함께 감사하고 업데이트합니다. 유지 관리자, 게시 시점, tarball 차이, 출처를 검증하며 위험한 패키지는 수동 검토로 넘깁니다. 전체 과정에서 보안과 무결성을 유지하며 의존성을 안전하게 업데이트할 때 사용하세요.

빠른 설치

Claude Code

추천
기본
npx skills add backnotprop/plannotator -a claude-code
플러그인 명령대체
/plugin add https://github.com/backnotprop/plannotator
Git 클론대체
git clone https://github.com/backnotprop/plannotator.git ~/.claude/skills/update-deps

Claude Code에서 이 명령을 복사하여 붙여넣어 스킬을 설치하세요

문서

Update Dependencies

Audit outdated packages, verify supply chain integrity, bump what's safe, defer what needs review, and log everything.

This process has three phases: discovery, integrity audit, and execution. The integrity audit is the most important — every package gets checked before it touches the lockfile.

Phase 1: Discovery

Run bun outdated to get the full list of packages with available updates.

bun outdated

Parse the output into a structured list. For each package, note:

  • Package name
  • Current version
  • Available update version
  • Whether it's age-gated (indicated by * in the output — the footnote "The * indicates that version isn't true latest due to minimum release age" confirms this)
  • Whether it's a runtime dep, dev dep, or peer dep

Also check whether any packages are blocked entirely by the age gate (like @pierre/diffs was when its minimum semver range couldn't resolve). Flag these separately — they may need minimumReleaseAgeExcludes in bunfig.toml.

Phase 2: Integrity Audit

This is the core of the process. Spawn one Sonnet sub-agent per package to run the integrity check in parallel. Sonnet is used here because these are independent, structured verification tasks that don't need heavier reasoning.

Each sub-agent receives the package name, current version, and target version, and performs the following checks:

Sub-agent prompt template

For each outdated package, spawn a Sonnet agent with this task:

You are auditing the npm package "{package}" for a version bump from {current} to {target}.

Run these checks and report back with a JSON object:

1. **Maintainer verification**: Check if maintainers changed between versions.
   npm view {package}@{current} maintainers --json
   npm view {package}@{target} maintainers --json
   Compare the two lists. Flag any additions or removals.

2. **Publish date and age**: Get the publish timestamp.
   npm view {package} time --json
   Extract the date for version {target}. Calculate days since publication.
   Flag if younger than 7 days.

3. **Provenance**: Check if the package has registry signatures or attestations.
   npm audit signatures (if not already run this session)
   Note whether the package has provenance attestations.

4. **Tarball diff**: Show what actually changed in the published package.
   npm diff --diff={package}@{current} --diff={package}@{target}
   Summarize the changes:
   - How many files changed
   - Are changes limited to version bumps, deps, and rebuilt dist? Or are there meaningful source changes?
   - Any new runtime dependencies added?
   - Any suspicious patterns (obfuscated code, eval(), network calls in unexpected places)

5. **Release notes**: Try to find what changed.
   Check the package's repository for release notes or changelog:
   npm view {package}@{target} repository.url
   gh release view v{target} --repo <owner/repo> (try with and without v prefix)
   Summarize the changelog if found.

Report your findings as JSON:

{{
  "package": "{package}",
  "from": "{current}",
  "to": "{target}",
  "age_days": <number>,
  "maintainers_changed": <boolean>,
  "maintainers_added": [],
  "maintainers_removed": [],
  "provenance": <boolean>,
  "new_runtime_deps": [],
  "files_changed": <number>,
  "has_source_changes": <boolean>,
  "changelog_summary": "<brief summary>",
  "suspicious_patterns": [],
  "verdict": "safe" | "review" | "defer",
  "verdict_reason": "<one sentence explanation>"
}}

Verdict guidelines:
- "safe": Same maintainers, no new runtime deps, changes match what changelog describes, no suspicious patterns
- "review": Minor concerns (e.g., new maintainer who is clearly from the same org, small new dep from known publisher)
- "defer": Maintainer changes from unknown accounts, new runtime deps with unclear purpose, suspicious code patterns, substantive API changes that need integration testing

Collecting results

As sub-agents complete, collect their JSON reports. If a sub-agent fails or times out, mark that package as "defer" with reason "audit failed".

Tier classification

After collecting all results, classify packages into tiers. This helps the user understand the risk profile at a glance:

TierDescriptionTypical action
Runtime, high surfaceLibraries your code calls directly (parsers, diff engines, UI libs)Check provenance, review diff, run tests
SDK/API depsThird-party service SDKs (agent SDKs, platform integrations)Read changelog for API changes, test integration
Dev-onlyType definitions, build tools, test frameworksUpdate freely — these don't ship
Build toolchainBun itself, compilers, bundlersMost caution — breakage affects all outputs

Phase 3: Execution

Bump safe packages

For all packages with verdict "safe":

bun update pkg1@version1 pkg2@version2 ...

If the update fails due to age gate conflicts (a package's minimum semver can't resolve), add it to minimumReleaseAgeExcludes in bunfig.toml and document why.

Log to supply chain notes

Write the full audit results to ~/.supply-chain/notes/<YYYY-MM-DD>.json:

{
  "date": "YYYY-MM-DD",
  "project": "plannotator",
  "bumped": [
    {
      "package": "...",
      "from": "...",
      "to": "...",
      "age_days": 0,
      "maintainers_changed": false,
      "provenance": false,
      "notes": "..."
    }
  ],
  "deferred": [
    {
      "package": "...",
      "current": "...",
      "available": "...",
      "age_days": 0,
      "maintainers_changed": false,
      "reason": "...",
      "review_by": "YYYY-MM-DD"
    }
  ],
  "excluded_from_age_gate": [
    {
      "package": "...",
      "reason": "..."
    }
  ]
}

Set review_by to 7 days from today for deferred packages.

Check previously deferred packages

Read all files in ~/.supply-chain/notes/ and collect any deferred packages from previous audits that are still at the same version in the current lockfile. These are packages that were deferred before and still haven't been updated.

To check: for each previously deferred entry, see if the current installed version matches the current field from the deferral note. If it does, the package is still deferred.

Phase 4: Recap

Present a clear summary to the user:

Updated

List each bumped package with version change and one-line reason it was safe.

Deferred

List each deferred package with version change and reason for deferral.

Still Deferred (from previous audits)

List any packages that were deferred in previous audit sessions and still haven't been bumped. Include the original deferral date and reason. This is the "you've been putting this off" section — it keeps deferred packages from being forgotten.

If the still-deferred list is empty, say so — that's a good sign.

Age Gate Exclusions

If any packages were added to minimumReleaseAgeExcludes, note them and why.

GitHub 저장소

backnotprop/plannotator
경로: .agents/skills/update-deps
0
agentsclaude-codecode-reviewcodexobsidianopencode

연관 스킬

llamaguard

기타

LlamaGuard는 폭력 및 혐오 발언 등 6가지 안전 범주에서 LLM 입력과 출력을 조정하기 위한 Meta의 70-80억 파라미터 모델입니다. 94-95% 정확도를 제공하며 vLLM, Hugging Face 또는 Amazon SageMaker를 사용해 배포할 수 있습니다. 이 기술을 사용하여 AI 애플리케이션에 콘텐츠 필터링 및 안전 가드레일을 손쉽게 통합하세요.

스킬 보기

cost-optimization

기타

이 Claude Skill은 리소스 적정화, 태깅 전략, 지출 분석을 통해 개발자들이 클라우드 비용을 최적화할 수 있도록 지원합니다. AWS, Azure, GCP에서 클라우드 비용을 절감하고 비용 거버넌스를 구현하기 위한 프레임워크를 제공합니다. 인프라 비용을 분석하거나, 리소스를 적정화하거나, 예산 제약을 충족해야 할 때 사용하세요.

스킬 보기

quantizing-models-bitsandbytes

기타

이 스킬은 bitsandbytes를 사용하여 LLM을 8비트 또는 4비트 정밀도로 양자화하며, 최소한의 정확도 손실로 50-75%의 메모리 감소를 달성합니다. 제한된 GPU 메모리에서 더 큰 모델을 실행하거나 추론을 가속화하는 데 이상적이며, INT8, NF4, FP4와 같은 형식을 지원합니다. 이 스킬은 HuggingFace Transformers와 통합되어 QLoRA 학습 및 8비트 옵티마이저를 가능하게 합니다.

스킬 보기

dispatching-parallel-agents

기타

이 Claude Skill은 3개 이상의 독립적인 문제를 동시에 조사하고 해결하기 위해 다중 에이전트를 배치합니다. 공유 상태나 의존성 없이 해결 가능한 무관련 장애 시나리오에 맞게 설계되었습니다. 핵심 기능은 병렬 문제 해결로, 각 독립 문제 영역마다 하나의 에이전트를 할당하여 효율성을 극대화합니다.

스킬 보기