Skip to content
Back to skills

Skill Dependency Management

ASecurity

Version updates (major/minor/patch), security patch application, transitive dependency resolution, monorepo dependency management, deprecation tracking, license compliance. Use when updating dependencies, managing versions, or addressing CVEs.

  • 4 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 7, 2026
developmentgobashgitapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 7, 2026

npx -y skills add saitarrun/Sdlc-ai-workflow --skill skill-dependency-management --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Skill Dependency Management?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Skill Dependency Management
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/saitarrun-skill-dependency-management/badge)](https://www.skillsdirectory.com/skills/saitarrun-skill-dependency-management)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: skill-dependency-management
description: Version updates (major/minor/patch), security patch application, transitive dependency resolution, monorepo dependency management, deprecation tracking, license compliance. Use when updating dependencies, managing versions, or addressing CVEs.
version: 1.0.0
---

# Skill: Dependency Management

Stay current. Stay secure. Minimize version mismatch.

## Version Updates

**Semantic Versioning**:
- `1.0.0` → `2.0.0`: Breaking change (test, update code)
- `1.0.0` → `1.1.0`: New feature (backward-compatible, usually safe)
- `1.0.0` → `1.0.1`: Bug fix (safe to update)

## Security Patch Strategy

```bash
# 1. Check for vulnerabilities
npm audit  # or pip check, cargo audit

# 2. Update vulnerable packages
npm update lodash@4.17.21

# 3. Test changes
npm test

# 4. Commit & push
git commit -m "fix(deps): update lodash to patch CVE-2021-23337"
```

## Transitive Dependency Hell

```
app → requests@2.28.0
app → urllib3@1.26.0
app → certifi@2022.9.24

requests → urllib3@1.25.0  # Different version!
```

**Solution**: Lock files (requirements.txt, package-lock.json, Cargo.lock)

## Monorepo Dependencies

**Shared dependencies** (lock once):
```
root/
  Cargo.lock  # All crates use this
  crates/
    auth/
    api/
    db/
```

## Deprecation Tracking

```
# Checklist when you deprecate something
- [ ] Announce (email, docs, header warning)
- [ ] Timeline (6 months warning)
- [ ] Alternatives (what should users use?)
- [ ] Test (ensure new way works)
- [ ] Remove (after timeline)
```

---

**Status**: Ready for dependency work  
**Best for**: Version updates, security patches, CVE management

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…