Skip to content

feat(dev-hooks): dependency-upgrade major pass checks for security advisories - #29

Open
mickzijdel wants to merge 1 commit into
mainfrom
feat/dependency-upgrade-security-relevance
Open

mickzijdel wants to merge 1 commit into
mainfrom
feat/dependency-upgrade-security-relevance

Conversation

@mickzijdel

Copy link
Copy Markdown
Owner

Summary

  • dependency-upgrade's major pass now asks for a security-advisory check (GitHub Security Advisories / the ecosystem's own CVE/OSV database) for the version being left behind, alongside the changelog WebFetch it already does — stated either way ("no known advisories" or the advisory id) in the commit body.
  • A deferred major (one that can't get green) now explicitly flags at the top of its plans/deferred-upgrades.md entry if the advisory check found a live CVE, so a cooldown or a failed migration doesn't silently leave a known vulnerability unaddressed.
  • The final summary step now calls out which upgrades closed a known advisory.
  • Bumped dev-hooks plugin version 2.33.0 → 2.33.1 (patch).

Source

commit-digest run reviewing nateberkopec/dotfiles. Commit 1c95511 ("Add lock-driven dependency software factory") adds a scheduled GitHub Actions workflow whose dependency-update PRs always lead with security impact per candidate ("Security: relevant CVEs/advisories, or explicitly 'none found'"). The full workflow (GitHub Actions + Copilot/Codex model tuning, cask/mise-binary self-update, snooze-via-PR-comment) is specific to Nate's personal machine bootstrap and out of scope here, but the "always state security relevance, even when it's none" framing was a real gap in dependency-upgrade's existing major-bump handling, which already reads changelogs but never explicitly checked advisories.

Test plan

  • uv run pytest -q — 697 passed
  • claude plugin validate --strict . — passed
  • No scripts touched (prose-only change to SKILL.md + version bump), so shfmt/shellcheck/jscpd don't apply.

Generated by Claude Code

…visories

Nate Berkopec's dotfiles added an AI-driven dependency-update workflow (#554)
whose PR descriptions lead with security impact for every candidate. This
skill already WebFetches changelogs for major bumps but never asked whether
the version being left behind has a live CVE/advisory — add that check and
surface it in the commit body, the deferred-upgrades report, and the final
summary so a stalled major doesn't silently sit on a known vulnerability.
mickzijdel pushed a commit that referenced this pull request Aug 21, 2026
Reviewed 14 nateberkopec/dotfiles commits and 20 ai-productivity-digest
feed items. One implement (dev-hooks PR #29); rest logged as
deferred/duplicate/rejected/out-of-scope.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants