Skip to content
Back to skills

Dependency Management

ASecurity

Python dependency and environment management for multi-service or monorepo python backends. Use when adding, upgrading, or removing packages, responding to CVE floor alerts, creating service requirements, debugging install failures, or running pip-compile. Enforces the pip-compile locked-file workflow and tiered dependency hierarchy.

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentspythonbashdockerdebuggingbackendsecurity

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 14 files and shows the line behind each finding

Scanned October 3, 2026

npx -y skills add richfrem/agent-plugins-skills --skill dependency-management --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dependency Management?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dependency Management
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/richfrem-dependency-management-agent-plugins-skills/badge)](https://www.skillsdirectory.com/skills/richfrem-dependency-management-agent-plugins-skills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dependency-management
plugin: dependency-management
description: >
  Python dependency and environment management for multi-service or monorepo python backends.
  Use when adding, upgrading, or removing packages, responding to CVE floor alerts,
  creating service requirements, debugging install failures, or running pip-compile.
  Enforces the pip-compile locked-file workflow and tiered dependency hierarchy.
allowed-tools: Bash, Read, Write
---

## Dependencies

Requires Python 3.8+ (standard library only).

---

# Dependency Management (`dependency-management`)

Python dependency management enforcing the pip-compile locked-file workflow across core and service tiers.

## Contents

- [Dependencies](#dependencies)
- [Constraints](#constraints)
- [Quick start](#quick-start)
- [Workflow](#workflow)
- [Verification](#verification)
- [References](#references)

## Constraints

- **Never install manually**: Do not run `pip install <pkg>` directly to resolve dependency issues.
- **Never edit lockfiles manually**: `*.txt` lockfiles are machine-generated by `pip-compile`.
- **Commit as pairs**: Stage and commit both `*.in` and `*.txt` lockfiles together.
- **Security floor pins**: Security floor pins in `*.in` files must use `>=` syntax (e.g. `cryptography>=46.0.5`), never `==`.
- **Container contract**: Dockerfiles must copy `requirements.txt` before code and run `pip install -r requirements.txt`.

## Quick start

1. Edit package intent in `src/requirements-core.in` or `src/services/<service>/requirements.in`.
2. Compile lockfile:
   ```bash
   pip-compile src/requirements-core.in --output-file src/requirements-core.txt
   ```
3. Sync environment:
   ```bash
   pip-sync src/requirements-core.txt
   ```

## Workflow

1. **Declare**: Update the version constraint in the correct `.in` file.
2. **Lock**: Run `pip-compile` on core first, then downstream services inheriting core via `-r`.
3. **Security Floors**: For GHSA/CVE advisories, bump floor constraint (`>=`) in `.in` and recompile.
4. **Build & Verify**: Rebuild affected Docker/Podman container to verify clean installation.

## Verification

```bash
# Verify lockfile matches compilation
pip-compile --dry-run src/requirements-core.in
# Verify patched package is present in lockfiles
grep -i "<package-name>" src/requirements-core.txt src/services/*/requirements.txt
```

Log unresolvable conflicts to [Map Debt](references/map-debt.md) and record completions in [evolution-log.md](references/evolution-log.md).

## References

- [acceptance-criteria.md](references/acceptance-criteria.md) — Acceptance criteria for lockfile hygiene and CVE mitigations.
- [fallback-tree.md](references/fallback-tree.md) — Procedural fallback tree for compilation conflicts and missing tools.
- [DEPENDENCY_MANAGEMENT.md](references/DEPENDENCY_MANAGEMENT.md) — Deep architectural guide and workflow diagrams.
- [DEPENDENCY_MANIFEST.md](references/DEPENDENCY_MANIFEST.md) — Complete repository dependency tier hierarchy.

Files in this skill

  • SKILL.md6.9 KB
  • acceptance-criteria.md3.1 KB
  • evals/evals.json1.6 KB
  • evals/results.tsv301 B
  • fallback-tree.md1.4 KB
  • references/DEPENDENCY_MANAGEMENT.md44 B
  • references/DEPENDENCY_MANIFEST.md42 B
  • references/acceptance-criteria.md42 B
  • references/dependency-management.md39 B
  • references/fallback-tree.md36 B
  • references/policy_details.md37 B
  • references/python_dependency_workflow.mmd50 B
  • requirements.in22 B
  • requirements.txt22 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…