Agent skill · Security

dependency-management

Version pinning, vulnerability scanning, monorepo patterns, and upgrade workflows

Cosmic Stack3,294★ · 2 repos on radarProfile →
claude-codeMIT
Install
npx skills add cosmicstack-labs/mercury-agent-skills --skill dependency-management --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 1
SKILL.md size: 2 KB
Bundled scripts: none
Version: 1.0.0
Declared author: cosmicstack-labs
Path: categories/development/dependency-management/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 364
Language: JavaScript
Read our review of the source →

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# Dependency Management Safely manage project dependencies at scale. ## Version Strategy ### Pinning Approaches | Strategy | Format | Risk | Best For | |----------|--------|------|----------| | Exact | `1.2.3` | Low | Docker, CI, production | | Caret | `^1.2.3` | Medium | Libraries, apps with good tests | | Tilde | `~1.2.3` | Low-Medium | Conservative updates | | Range | `>=1.2.3 <2.0.0` | High | Rare, legacy | | Floating | `*` | Very High | Never in production | **Rule**: Pin exact versions for production, caret for libraries. ## Vulnerability Scanning ### Tools - **npm audit** / `yarn audit` — quick JS check - **Dependabot** — GitHub-native, auto PRs - **Snyk** — deeper scanning, prioritization - **Trivy** — container scanning - **OWASP Dependency-Check** — Java/.NET ### Workflow 1. Scan on every PR (fail on critical/high) 2. Weekly full scan of all repos 3. Patch critical (<7 days), high (<30 days) 4. Track CVEs by severity in dashboard 5. SBOM generation per release ## Monorepo Patterns - Use workspaces (npm/yarn/pnpm workspaces) - Shared dependency versions (single source of truth) - Independent vs locked version strategy - Deduplicate (npx dedupe after major changes) - Audit

What's inside
Steps it walks through
  1. Version Strategy
  2. Pinning Approaches
  3. Vulnerability Scanning
  4. Tools
  5. Workflow
  6. Monorepo Patterns
  7. Upgrade Workflow
More from mercury-agent-skills
All skills →
About this skill
What does the dependency-management skill do?

Version pinning, vulnerability scanning, monorepo patterns, and upgrade workflows

How do I install it?

Run `npx skills add cosmicstack-labs/mercury-agent-skills --skill dependency-management --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From cosmicstack-labs/mercury-agent-skills, a repository with 364 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going