本文へ移動
cccskills
無料GitHub で公開

dep-resolve

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md4.4 KB
  • evals/evals.json2.7 KB
  • evals/trigger-eval.json1.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Vulnetix Dependency Resolution Skill

Use when

  • fix proposed a version bump but <pm> install errored on peer-dep conflict.
  • A transitive vulnerable dep needs pinning without bumping the direct dependency.
  • Lockfile resolution fails after a merge — diagnose which deps disagree.
  • Considering a package-manager override (npm overrides, pnpm overrides, yarn resolutions).
  • Last-resort: copy patched upstream code inline as first-party (Type A0 inline).

Don't use for

  • Initial fix proposal — use fix first.
  • Just looking up safe versions — use dependency-choice.
  • Multi-CVE upgrade orchestration — use @dep-upgrade-orchestrator.

Conventions

Follows skills/_lib/contract.md. In short: use the vulnetix_* MCP tools when the agent has them and the CLI otherwise — both shape their own output, so there is no jq step any more. Independent calls go out as concurrent Bash tool calls in one message. One trailing suggestion, not a playbook. See the contract for surface selection, output style and memory writes.

When fix proposes a version bump but the lockfile resolution fails (peer-dep conflict, transitive constraint, etc.), use this skill to find a compatible set.

Step 1: Load capabilities + memory

Read .vulnetix/capabilities.yaml (derived.primary_package_manager decides which lockfile to read) and .vulnetix/memory.yaml (decisions / safe-harbour notes).

Step 2: Map the conflict

# npm/pnpm/yarn
npm ls "$PACKAGE" 2>&1 || pnpm why "$PACKAGE" || yarn why "$PACKAGE"
# pip
pip show "$PACKAGE"
# go
go mod why "$PACKAGE"
# cargo
cargo tree -i "$PACKAGE"

Pick the command for the detected package manager. Capture the dep tree paths.

Step 3: Pull safe-version graph

vulnetix vdb versions "$PACKAGE" -o json
vulnetix vdb fixes "$PACKAGE" -o json

For each candidate target version:

  • Cross-check transitive constraints from Step 2
  • Cross-check known vulns at that version (vdb vulns)

Step 4: Propose resolution

Prefer (in order):

  1. Single bump — newest patch version that fixes the vuln and satisfies constraints
  2. Override — package-manager override (npm overrides, pnpm pnpm.overrides, yarn resolutions)
  3. Safe-harbour inline — copy upstream patch into repo as first-party code (link to fix Type A0 path)
  4. Workaround only — detection-rules <vuln-id> while waiting for upstream

Step 5: Apply (with confirmation)

For option 1: edit the manifest, run <pm> install (npm/pnpm/yarn/pip/go/cargo). For option 2: write the override block, run install. For option 3: hand off to fix Type A0. For option 4: hand off to detection-rules.

Always pause for user approval before writing manifest edits.

Step 6: Verify

Suggest verify-fix <vuln-id> after the resolution lands.

Memory update

event: dep-resolve with the chosen path.

Edge cases & gotchas

  • Dep-tree diagnosis uses package-manager-specific commands: npm ls, pnpm why, yarn why, pip show, go mod why, cargo tree -i. Wrong PM = misleading output.
  • Override semantics differ per ecosystem: npm overrides is post-install hoist, pnpm pnpm.overrides is install-time pinning, yarn resolutions works with both classic and Berry but with different scoping.
  • Pip has no clean override — pinning the transitive in requirements.txt + --no-deps for the parent is the cleanest workaround.
  • Go replace directives work only when the module path is identical (no rename through fork).
  • Cargo [patch] requires the patched crate at a real path or git ref; cannot inline a hex string.
  • Inline-as-first-party (Type A0) introduces license obligations from the upstream package — copy the LICENSE file too.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

dashboard

無料

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

eol-check

無料

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating a deploy against EOL deps, or producing a remediation roadmap.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target. Use when validating that a fix actually closed the vulnerability path, confirming a patch deployed correctly, or producing a copy-pasteable test command for QA. The skill never executes — the user runs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Vulnetix のスキルをすべて見る

このスキルの問題を報告する