Use when multiple open Dependabot pull requests should be consolidated into one issue and one pull request, with superseded Dependabot PRs closed.
Use when fixing GitHub Advanced Security / CodeQL findings, especially URL validation, webview rendering, preview extraction, and sanitizer regressions.
Use when updating npm dependencies, adding packages, fixing npm audit vulnerabilities, or preparing build/PR for dependency changes. Enforces zero vulnerabilities at moderate/high/critical and requires regression tests for vulnerability-driven upgrades.