Repository navigation
feat(dev-hooks): dependency-upgrade major pass checks for security advisories - #29
Open
mickzijdel wants to merge 1 commit into
Open
mickzijdel wants to merge 1 commit into
mickzijdel wants to merge 1 commit into
Conversation
…visories Nate Berkopec's dotfiles added an AI-driven dependency-update workflow (#554) whose PR descriptions lead with security impact for every candidate. This skill already WebFetches changelogs for major bumps but never asked whether the version being left behind has a live CVE/advisory — add that check and surface it in the commit body, the deferred-upgrades report, and the final summary so a stalled major doesn't silently sit on a known vulnerability.
mickzijdel
pushed a commit
that referenced
this pull request
Aug 21, 2026
Reviewed 14 nateberkopec/dotfiles commits and 20 ai-productivity-digest feed items. One implement (dev-hooks PR #29); rest logged as deferred/duplicate/rejected/out-of-scope.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
dependency-upgrade's major pass now asks for a security-advisory check (GitHub Security Advisories / the ecosystem's own CVE/OSV database) for the version being left behind, alongside the changelogWebFetchit already does — stated either way ("no known advisories" or the advisory id) in the commit body.plans/deferred-upgrades.mdentry if the advisory check found a live CVE, so a cooldown or a failed migration doesn't silently leave a known vulnerability unaddressed.dev-hooksplugin version 2.33.0 → 2.33.1 (patch).Source
commit-digestrun reviewingnateberkopec/dotfiles. Commit1c95511("Add lock-driven dependency software factory") adds a scheduled GitHub Actions workflow whose dependency-update PRs always lead with security impact per candidate ("Security: relevant CVEs/advisories, or explicitly 'none found'"). The full workflow (GitHub Actions + Copilot/Codex model tuning, cask/mise-binary self-update, snooze-via-PR-comment) is specific to Nate's personal machine bootstrap and out of scope here, but the "always state security relevance, even when it's none" framing was a real gap independency-upgrade's existing major-bump handling, which already reads changelogs but never explicitly checked advisories.Test plan
uv run pytest -q— 697 passedclaude plugin validate --strict .— passedSKILL.md+ version bump), so shfmt/shellcheck/jscpd don't apply.Generated by Claude Code