本文へ移動
cccskills
無料GitHub で公開

dependency-manager

Dependency management, vulnerability scanning, license compliance, package updates, and monorepo tooling. Use when updating dependencies, auditing packages, managing licenses, or configuring package managers.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md3.1 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Dependency Manager

Package Management

Monorepo with pnpm

# pnpm-workspace.yaml
packages:
  - 'apps/*'
  - 'packages/*'

# .npmrc
shamefully-hoist=true
strict-peer-dependencies=false
auto-install-peers=true

Dependency Updates

# Check for updates
pnpm outdated

# Update all dependencies
pnpm update --latest

# Update specific package
pnpm update react@latest

# Interactive update
pnpm update --interactive

Security Auditing

Automated Scanning

// scripts/security-audit.ts
import { execSync } from 'child_process';

async function securityAudit() {
  try {
    const result = execSync('pnpm audit --json', { encoding: 'utf-8' });
    const audit = JSON.parse(result);
    
    const critical = audit.advisories.filter(a => a.severity === 'critical');
    const high = audit.advisories.filter(a => a.severity === 'high');
    
    if (critical.length > 0) {
      console.error(`❌ ${critical.length} critical vulnerabilities found`);
      process.exit(1);
    }
    
    if (high.length > 0) {
      console.warn(`⚠️ ${high.length} high severity vulnerabilities`);
    }
  } catch (error) {
    console.error('Audit failed:', error);
    process.exit(1);
  }
}

Lock File Integrity

# Verify lock file
pnpm install --frozen-lockfile

# Check for lock file drift
pnpm install && git diff --exit-code pnpm-lock.yaml

License Compliance

// scripts/check-licenses.ts
import checker from 'license-checker';

const ALLOWED_LICENSES = [
  'MIT',
  'Apache-2.0',
  'BSD-3-Clause',
  'ISC',
  'CC0-1.0'
];

const FORBIDDEN_LICENSES = [
  'GPL-2.0',
  'GPL-3.0',
  'AGPL-3.0'
];

checker.init({ start: '.' }, (err, packages) => {
  if (err) process.exit(1);
  
  for (const [name, info] of Object.entries(packages)) {
    const licenses = Array.isArray(info.licenses) 
      ? info.licenses 
      : [info.licenses];
    
    for (const license of licenses) {
      if (FORBIDDEN_LICENSES.includes(license)) {
        console.error(`❌ Forbidden license ${license} in ${name}`);
        process.exit(1);
      }
    }
  }
  
  console.log('✅ All licenses compliant');
});

Bundle Size Analysis

// scripts/analyze-bundle.ts
import { analyze } from 'webpack-bundle-analyzer';

async function analyzeBundle() {
  const stats = await import('./dist/stats.json');
  
  const largeModules = stats.modules
    .filter(m => m.size > 100000)
    .sort((a, b) => b.size - a.size);
  
  console.log('Large modules (>100KB):');
  largeModules.forEach(m => {
    console.log(`  ${m.name}: ${(m.size / 1024).toFixed(2)}KB`);
  });
}

Dependency Graph

# Visualize dependencies
pnpm list --depth=10 --json | jq '.'

# Find why a package is installed
pnpm why lodash

# Find duplicate packages
pnpm dedupe --check
pnpm dedupe

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

ai-sdk

無料

Vercel AI SDK expert guidance. Use when building AI-powered features — chat interfaces, text generation, structured output, tool calling, agents, MCP integration, streaming, embeddings, reranking, image generation, or working with any LLM provider.

日本語の概要は準備中です。原文の説明を表示しています。

garochee33/DSH42026年10月9日 更新

Algorithm design and analysis skill for DSH; use when working on optimization, data structures, or computational procedures.

日本語の概要は準備中です。原文の説明を表示しています。

garochee33/DSH42026年10月9日 更新

Design and implement scalable API gateways, RESTful APIs, GraphQL endpoints, WebSocket handlers, and microservice communication patterns. Use when creating API routes, designing endpoints, implementing middleware, or setting up service mesh architectures.

日本語の概要は準備中です。原文の説明を表示しています。

garochee33/DSH42026年10月9日 更新

best-of-n

無料

Implement a task N ways in parallel and pick the best. Spawns multiple subagents in isolated worktrees, evaluates all candidates, and applies the winner. Use when asked to "best of n", "try multiple approaches", "parallel implementations", "/best-of-n", or "/bon".

日本語の概要は準備中です。原文の説明を表示しています。

garochee33/DSH42026年10月9日 更新

check

無料

Check your work with a verification subagent. Spawns a verifier that reviews diffs, runs builds and tests, and evaluates correctness. Use when asked to "check work", "verify changes", "self-verify", "/check", "/verify", "/check-work", or "/self-verify".

日本語の概要は準備中です。原文の説明を表示しています。

garochee33/DSH42026年10月9日 更新

CI/CD pipeline design, GitHub Actions workflows, deployment automation, infrastructure as code, and release management. Use when setting up CI/CD, automating deployments, configuring build pipelines, or managing releases.

日本語の概要は準備中です。原文の説明を表示しています。

garochee33/DSH42026年10月9日 更新

garochee33 のスキルをすべて見る

このスキルの問題を報告する