Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة

auditing-dependency-bumps

النجوم٣٢
التفرعات٢٣
آخر تحديث٩ يونيو ٢٠٢٦ في ١٤:٠٧

Use when reviewing a Dependabot (or similar) dependency-bump PR — npm/pnpm minor/patch group bumps or GitHub Actions SHA bumps — and you need to do a supply-chain audit before approving and merging. Covers downloading and inspecting package contents, checking for known compromises, the git-tap trick for Dependabot CI, and the approve/merge flow.

التثبيت

التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.

SKILL.md
readonly