skill
职业分类
描述
更新
bump-transitive-dependency
软件开发工程师
Bump a transitive dependency to a patched version using pnpm. Use when Dependabot reports a security vulnerability in a transitive dependency and cannot auto-update it, or when the user mentions bumping, upgrading, or patching a transitive dependency.
2026-05-19
fix-security-vulnerabilities
信息安全分析师
Fetch all open security vulnerabilities from Dependabot (or pnpm audit as fallback) and bump every affected dependency to its patched version. Use when the user asks to fix, resolve, or address all security vulnerabilities, Dependabot alerts, or audit findings.
2026-05-19