本文へ移動
cccskills
無料GitHub で公開

review-renovate

Review Renovate bot PRs that update GitHub Actions dependencies. Verifies supply chain integrity by checking pinned commit SHAs against upstream tagged releases, reviews changelogs for breaking changes, and confirms compatibility with existing workflow configurations. Use when a Renovate PR updates GitHub Actions in .github/workflows/.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md2.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Review Renovate GitHub Actions PRs

You are reviewing a Renovate bot PR that updates GitHub Actions dependencies. Your job is to verify supply chain integrity and ensure the upgrades won't break CI/CD workflows.

Inputs

You will be given a PR number or URL. Use gh CLI to fetch PR details and diff.

Steps

1. Fetch PR metadata and diff

gh pr view <PR> --json title,body,files,commits,author,headRefName
gh pr diff <PR>

Confirm the PR author is app/renovate. If not, flag this immediately — it may not be an automated dependency update.

2. Identify all action version changes

From the diff, extract each changed action:

  • Full action name (e.g., oven-sh/setup-bun)
  • Old version tag and pinned SHA
  • New version tag and pinned SHA
  • Update type (patch, minor, major)

3. Verify pinned SHAs against upstream tags

For every action being updated, verify both old and new SHAs match the claimed version tags:

gh api repos/{owner}/{repo}/git/ref/tags/{version} --jq '.object.sha'

Compare each result against the SHA in the workflow file. If any SHA does not match, stop and report a supply chain integrity failure. Do not approve the PR.

4. Review changelogs for breaking changes

From the PR body (Renovate includes release notes), check each updated action for:

  • Removed inputs or outputs that the workflows currently use
  • Changed default behavior for inputs the workflows rely on
  • New required inputs
  • Major version bumps (these almost always have breaking changes)

5. Check workflow compatibility

Read the affected workflow files and verify:

  • No removed or renamed inputs are being used
  • No changed defaults affect current behavior
  • The action's runtime requirements are still met (e.g., Node.js version compatibility)

6. Report findings

Present a summary table:

ActionOldNewTypeSHA verified
.........patch/minor/majoryes/NO

Then state:

  • Whether all SHAs are verified
  • Whether any breaking changes were found
  • Whether the workflows remain compatible
  • A clear safe to merge or do not merge recommendation

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reference for using Plannotator (its `plannotator` tool when you have one, otherwise the CLI): plan review, code review, annotating files, URLs, folders, and running local apps, annotating the last assistant message, browsing archived plan decisions, exporting or sharing Guided Reviews, and the Plannotator Inbox (messages and questions the person answers later, without blocking you). Invoke when asked to use Plannotator for anything not covered by a more specific plannotator-* skill.

日本語の概要は準備中です。原文の説明を表示しています。

backnotprop/plannotator9,3432026年10月11日 更新

Open Plannotator's annotation UI for a markdown file, HTML file, URL, or folder and then respond to the returned annotations.

日本語の概要は準備中です。原文の説明を表示しています。

backnotprop/plannotator9,3432026年10月11日 更新

Open Plannotator's annotation UI for a file, folder, or URL, then address the returned annotations.

日本語の概要は準備中です。原文の説明を表示しています。

backnotprop/plannotator9,3432026年10月11日 更新

Open Plannotator's annotation UI for a markdown file, plain-text config file (.yaml, .json, .toml, .ini, .csv, .log, …), HTML file, URL, or folder and then respond to the returned annotations.

日本語の概要は準備中です。原文の説明を表示しています。

backnotprop/plannotator9,3432026年10月11日 更新

Analyze a user's Plannotator plan archive to extract denial patterns, feedback taxonomy, evolution over time, and actionable prompt improvements — then produce a polished HTML dashboard report. Falls back to Claude Code ExitPlanMode denial reasons when Plannotator data is unavailable.

日本語の概要は準備中です。原文の説明を表示しています。

backnotprop/plannotator9,3432026年10月11日 更新

Open Plannotator on the latest rendered assistant message and use the returned annotations to revise that message or continue.

日本語の概要は準備中です。原文の説明を表示しています。

backnotprop/plannotator9,3432026年10月11日 更新

backnotprop のスキルをすべて見る

このスキルの問題を報告する