Skip to main content

run-dependency-audit

Surveys outdated and vulnerable dependencies across the frontend (Bun) and backend (pip/uv) toolchains and triages findings by severity and exposure. Use when a dependency manifest or lockfile changes, or when asked to check for outdated packages, security advisories, or whether a dependency needs bumping.

설치로 이동

소스 정보

저장소
districtr/districtr-v2
최근 소스 활동
2026년 9월 18일 14:42
감지된 SKILL.md 언어
영어
스타
6
포크
3

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
run-dependency-audit
description
Surveys outdated and vulnerable dependencies across the frontend (Bun) and backend (pip/uv) toolchains and triages findings by severity and exposure. Use when a dependency manifest or lockfile changes, or when asked to check for outdated packages, security advisories, or whether a dependency needs bumping.
paths
["app/package.json","app/bun.lock","backend/requirements.txt"]
# Dependency audit This is a survey-and-triage procedure, not an auto-upgrade tool: it enumerates what's outdated or flagged, and the output is findings to file, not diffs to apply. Bumping a dependency is a separate, deliberate change — do it one package at a time, with its own quality-gate run. ## Frontend (Bun) Bun is the frontend package manager (`app/bun.lock`) and has both checks built in — no extra tooling needed: ```bash cd app && bun outdated # every dependency vs. its latest matching/available version cd app && bun audit # known vulnerabilities in installed packages, via the npm advisory DB ``` ## Backend (pip / uv) `backend/requirements.txt` (a uv-generated lockfile) is the source of truth — `backend/pyproject.toml` holds only tool config, not dependency declarations. ```bash docker-compose exec backend pip list --outdated # installed vs. latest on PyPI uvx pip-audit -r backend/requirements.txt # known vulnerabilities, run from repo root ``` `pip list --outdated` needs the container (it reads the installed environment); `pip-audit` reads the lockfile directly, so `uvx` runs it on the host without installing anything. If `uvx pip-audit` crashes in `ensurepip` (seen 2026-09-03 on macOS), run it inside the container instead: `docker-compose exec backend pip install -q pip-audit && docker-compose exec backend pip-audit -r requirements.txt`. Triage findings by severity, actual exposure, and update cost, then file them (one issue per package or tightly-related group) rather than upgrading inline — a bump belongs in its own PR so a regression bisects to it alone. A Next.js major bump follows the official upgrade guide and codemods, one version at a time.
GitHub에서 보기