dependency-management
Version pinning, vulnerability scanning, monorepo patterns, and upgrade workflows
npx skills add cosmicstack-labs/mercury-agent-skills --skill dependency-management --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# Dependency Management Safely manage project dependencies at scale. ## Version Strategy ### Pinning Approaches | Strategy | Format | Risk | Best For | |----------|--------|------|----------| | Exact | `1.2.3` | Low | Docker, CI, production | | Caret | `^1.2.3` | Medium | Libraries, apps with good tests | | Tilde | `~1.2.3` | Low-Medium | Conservative updates | | Range | `>=1.2.3 <2.0.0` | High | Rare, legacy | | Floating | `*` | Very High | Never in production | **Rule**: Pin exact versions for production, caret for libraries. ## Vulnerability Scanning ### Tools - **npm audit** / `yarn audit` — quick JS check - **Dependabot** — GitHub-native, auto PRs - **Snyk** — deeper scanning, prioritization - **Trivy** — container scanning - **OWASP Dependency-Check** — Java/.NET ### Workflow 1. Scan on every PR (fail on critical/high) 2. Weekly full scan of all repos 3. Patch critical (<7 days), high (<30 days) 4. Track CVEs by severity in dashboard 5. SBOM generation per release ## Monorepo Patterns - Use workspaces (npm/yarn/pnpm workspaces) - Shared dependency versions (single source of truth) - Independent vs locked version strategy - Deduplicate (npx dedupe after major changes) - Audit
- Version Strategy
- Pinning Approaches
- Vulnerability Scanning
- Tools
- Workflow
- Monorepo Patterns
- Upgrade Workflow
What does the dependency-management skill do?
Version pinning, vulnerability scanning, monorepo patterns, and upgrade workflows
How do I install it?
Run `npx skills add cosmicstack-labs/mercury-agent-skills --skill dependency-management --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From cosmicstack-labs/mercury-agent-skills, a repository with 364 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.