| name | dart-deps |
| description | DART Deps: triage and shepherd dependency and bot pull requests |
dart-deps
Use this skill in Codex to run the DART dart-deps workflow. The editable
workflow source lives in .claude/commands/; this file is its generated adapter
in the shared .agents/skills/ catalog.
Invocation
- Claude Code/OpenCode:
/dart-deps <arguments>
- Codex:
$dart-deps <arguments>
Treat the text after the skill name as $ARGUMENTS. When the workflow
references $1, $2, etc., map those to the positional values supplied by the
user.
Command Body
Triage and shepherd dependency and bot PRs: $ARGUMENTS
Required Reading
@AGENTS.md
@docs/onboarding/ci-cd.md
@docs/onboarding/contributing.md
Scope
Handle automated dependency and maintenance PRs: Dependabot GitHub Action
version bumps and the scheduled lockfile PRs opened by update_lockfiles.yml.
Default to read-only triage; merging any bot PR is an explicit approval gate.
Workflow
- List open bot PRs:
gh pr list --repo dartsim/dart --state open \
--search "author:app/dependabot OR author:app/github-actions" \
--json number,title,headRefName,author
- For each PR, review the diff (
gh pr diff <PR_NUMBER>):
- Action bumps: confirm the new ref is a pinned commit SHA and sanity-check
the upstream changelog for the bumped version.
- Lockfile PRs: confirm the regenerated lockfile provenance matches the
workflow that produced it and that no unrelated content changed.
- Confirm CI is green for the PR head:
gh pr checks <PR_NUMBER>.
- Merge a reviewed, CI-green bot PR only after explicit maintainer/user
approval, using the current head SHA and the repository merge method.
- Batch-report every triaged PR with its recommendation and status.
Output
- Table of open bot PRs with kind (action bump or lockfile), CI state, and
recommendation
- Diff-review notes per PR
- Which PRs were merged after explicit approval and which remain pending