원클릭으로
check-deps
Analyze Gradle dependencies for outdated versions, known CVEs, unnecessary transitive dependencies, and version conflicts
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Analyze Gradle dependencies for outdated versions, known CVEs, unnecessary transitive dependencies, and version conflicts
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
Answer questions about kite spots, weather forecasts, and live wind conditions from varun.surf by fetching its public LLM-friendly Markdown endpoints (llms.txt). Use when the user asks about a specific kite spot, current wind conditions, hourly/daily forecasts, or wants to compare spots/countries covered by varun.surf.
Stage and commit current changes with a well-crafted commit message following project conventions
Explain data flows, features, and code paths in the varun.surf application with visual diagrams and step-by-step breakdowns
Verify architecture health including layer violations, circular dependencies, package structure, and design pattern compliance
Quick security audit checking for hardcoded secrets, SSRF vectors, injection points, dependency issues, and missing security headers
Find concurrency issues including race conditions, deadlocks, unsafe shared state, and improper synchronization
SOC 직업 분류 기준
| name | check-deps |
| description | Analyze Gradle dependencies for outdated versions, known CVEs, unnecessary transitive dependencies, and version conflicts |
Analyze the project's Gradle dependencies for security vulnerabilities, version issues, and optimization opportunities.
Run the following commands to collect dependency data:
# Full dependency tree
./gradlew dependencies --configuration runtimeClasspath
# Check for dependency updates (if plugin available)
./gradlew dependencyUpdates 2>/dev/null || echo "Plugin not available"
# Build file for direct dependencies
cat build.gradle
Read build.gradle and extract:
Create a table of direct dependencies:
| Group | Artifact | Declared Version | Type |
|---|---|---|---|
| org.springframework.boot | spring-boot-starter-webflux | 3.5.x | implementation |
For each major dependency, check current latest versions:
Spring Ecosystem (check spring.io):
HTTP Clients:
JSON Processing:
Testing:
Build Plugins:
Check for known vulnerabilities in dependencies:
High-Risk Libraries to Verify:
Use WebSearch to check:
"[library-name] [version] CVE" site:nvd.nist.gov
"[library-name] security advisory" site:github.com
Known Historical Issues:
From the dependency tree output, identify:
Unnecessary Transitive Dependencies:
Large Transitive Trees:
Example exclusion:
implementation('org.example:library') {
exclude group: 'commons-logging', module: 'commons-logging'
}
Look for in the dependency tree:
-> indicators showing version resolution(*) indicating dependency was evictedExample conflict:
+--- com.squareup.okhttp3:okhttp:4.12.0
| \--- org.jetbrains.kotlin:kotlin-stdlib:1.9.10 -> 1.9.22 (*)
Resolution strategies:
configurations.all {
resolutionStrategy {
force 'org.example:library:1.2.3'
failOnVersionConflict()
}
}
Calculate and report:
## Dependency Analysis Report
### Summary
| Metric | Count |
|--------|-------|
| Direct dependencies | X |
| Transitive dependencies | Y |
| Outdated dependencies | Z |
| Version conflicts | N |
| Potential CVEs | M |
### Outdated Dependencies
| Dependency | Current | Latest | Severity | Notes |
|------------|---------|--------|----------|-------|
| org.springframework.boot:* | 3.4.0 | 3.5.0 | Medium | Minor version behind |
| com.squareup.okhttp3:okhttp | 4.11.0 | 4.12.0 | Low | Patch update |
### Security Vulnerabilities (CVEs)
#### Critical
| Dependency | Version | CVE | Description | Fix |
|------------|---------|-----|-------------|-----|
| (none found or list issues) |
#### High
| Dependency | Version | CVE | Description | Fix |
|------------|---------|-----|-------------|-----|
### Version Conflicts
| Artifact | Requested Versions | Resolved | Risk |
|----------|-------------------|----------|------|
| kotlin-stdlib | 1.9.10, 1.9.22 | 1.9.22 | Low |
### Unnecessary Transitive Dependencies
| Dependency | Pulled By | Reason to Exclude | Savings |
|------------|-----------|-------------------|---------|
| commons-logging | spring-* | Using SLF4J | ~60KB |
### Dependency Tree Highlights
// Notable branches from dependency tree +--- org.springframework.boot:spring-boot-starter-webflux | +--- io.projectreactor:reactor-core:3.6.x | +--- io.projectreactor.netty:reactor-netty-http:1.1.x
### Recommendations
#### Immediate Actions (Security)
1. Upgrade X to version Y (CVE-XXXX-XXXXX)
#### Short-term (Maintenance)
1. Update spring-boot to latest 3.5.x
2. Add version constraints for transitive dependencies
#### Long-term (Optimization)
1. Consider adding OWASP dependency-check plugin
2. Set up Dependabot for automated updates
### Suggested build.gradle Additions
```gradle
// Add dependency update checking
plugins {
id 'com.github.ben-manes.versions' version '0.51.0'
}
// Add OWASP CVE scanning
plugins {
id 'org.owasp.dependencycheck' version '9.0.9'
}
// Force consistent versions
configurations.all {
resolutionStrategy {
// Add any necessary version forcing
}
}
## Execution Steps
1. Run `./gradlew dependencies --configuration runtimeClasspath` via Bash
2. Read `build.gradle` to identify direct dependencies
3. Parse dependency tree for conflicts and transitive deps
4. Use WebSearch to check for recent CVEs on major dependencies
5. Compare versions against latest stable releases
6. Generate comprehensive report with actionable recommendations
## Notes
- Spring Boot manages many dependency versions via BOM - check parent version
- Focus on runtime dependencies; test scope is lower priority
- Some "conflicts" are normal (Gradle picks highest compatible version)
- CVE databases may have false positives for non-applicable vulnerabilities
- Consider dependency scope when evaluating necessity