name: sd-update-deps description: Use when open dependency-bot PRs need batch triage — classify every dependabot or renovate PR, merge the safe class sequentially under the housekeeping gate criteria, and park the rest with one-line recommendations. model: sonnet
SD Update Deps
Run this project-local skill for sd-update-deps and /sd:update-deps style
work. It batch-triages the open dependency-bot pull requests in the current
repository: classify every PR, merge the safe class strictly sequentially
under the housekeeping gate criteria, and park everything else with a
one-line recommendation.
This command triages and merges; it does not upgrade dependencies itself. It never edits dependency manifests or lockfiles, never pushes to bot branches, and never opens PRs of its own. The housekeeping gate criteria are the merge authority: this skill adds no second merge path with weaker criteria.
Sandbox-safe tool execution
Run every gh, uv, pip, ruff, or npm command shown in this workflow
through bash "$SD_PACK_TOOLCHAIN" run -- <tool> [args...], with
$SD_PACK_TOOLCHAIN resolved by the bootstrap in
../sd-help/references/pack-helper-resolution.md.
The argv-safe wrapper changes only documented cache variables and preserves
auth/config state. If it is missing or reports a cache-setup failure, stop with
that diagnostic; do not retry the tool bare or redirect GH_CONFIG_DIR.
When to use
Run this command when dependency-bot PRs have accumulated and the user wants one batched triage pass instead of PR-by-PR manual decision rounds.
- Scope: open PRs in this repository authored by dependency bots —
dependabotandrenovate, including their[bot]account forms. - Human-authored PRs are out of scope. Leave them to
sd-review-prandsd-housekeeping. - Red dependency PRs are parked, not fixed here. Recommend
sd-fix-cifor the ones worth rescuing. - One repository per run: the current checkout's GitHub repository.
- Positioning:
sd-housekeepingwraps up one stream's own ready PR; this command applies the same merge criteria across the dependency-bot backlog. Neither replaces the other.
Arguments
Arguments arrive as free text with the invocation, as key=value pairs and
bare flags. Unknown argument names are an error, not a silent skip: stop and
report them before touching any PR. This skill reads no environment
variables; every tuning knob is an argument.
include-runtime-minor— bare flag. Add runtime-dependency minor updates to the auto-merge class for this run. Off by default: without it, runtime minors are parked for manual review.dry-run— bare flag. Classify and emit the full report only; perform no merges and no other mutations.
Workflow
- Enumerate. List open PRs with
gh pr listand keep only dependency-bot authors. Zero matching PRs is a valid result: report it and stop. - Classify every dependency PR on four axes:
- ecosystem — npm, pip, GitHub Actions, and so on, read from the bot metadata and the changed manifest files;
- semver delta — patch, minor, or major, read from the title and diff;
- security-advisory linkage — dependency bots flag security updates and link the advisory in the PR body or labels;
- dependency kind — development-only or runtime, read from the manifest section the PR changes.
- Assign each PR exactly one class:
- Auto-merge class: patch and minor dev-dependency updates, GitHub Actions SHA and pin bumps, and security patches.
- Runtime-dependency minors join the auto-merge class only when
include-runtime-minorwas passed. - No flag adds a major version update to the auto-merge class — majors are always manual.
- Everything else is parked.
- With
dry-run: emit the final report from the classification and stop here. No merges, no mutations of any kind. - Process the auto-merge class strictly sequentially, one PR at a time:
-
Start from the clean synchronized default branch and delegate the one merge attempt to the installed housekeeping owner:
SD_PACK_TOOLCHAIN="" for candidate in "${SD_AI_COMMAND_PACK_TOOLCHAIN:-}" \ "scripts/sd-ai-command-pack-toolchain.sh" \ "$HOME/.agents/bin/sd-ai-command-pack-toolchain.sh"; do if [ -f "$candidate" ]; then SD_PACK_TOOLCHAIN="$candidate"; break; fi done [ -n "$SD_PACK_TOOLCHAIN" ] || { printf '%s\n' "error: sd-ai-command-pack toolchain not found; checked SD_AI_COMMAND_PACK_TOOLCHAIN, scripts/, and \$HOME/.agents/bin. Reinstall the command pack." >&2; exit 1; } bash "$SD_PACK_TOOLCHAIN" run -- sd-ai-command-pack-housekeeping.sh --dependency-pr <number>Housekeeping invokes the shared schema-versioned PR eligibility evaluator in
dependency-prmode, re-reads the exact PR head after checks and complete review-thread pagination, and performs the onlygh pr merge --match-head-commitmutation. Do not reconstruct checks, thread, head, or mergeability logic in this skill. -
Treat an
eligiblereceipt plus housekeeping's confirmed merge and clean default-branch report as success. If the evaluator returnsblockedorindeterminate, or GitHub refuses the merge, park that PR with the stable diagnostic from housekeeping. -
Re-enumerate the remaining open dependency PRs after every successful merge. Dependency bots may rebase when the default branch moves, so an earlier receipt is never evidence for a later attempt.
-
A red or unclean default branch stops the merge loop. Report all remaining auto-class PRs as parked pending a clean green default branch.
-
- Park everything outside the merged set with one line per PR: the PR
reference plus a concrete recommendation. Examples:
major — review the changelog and migration notes manuallyruntime minor — rerun with include-runtime-minor after reviewred CI — triage with sd-fix-ciunresolved review thread — resolve with the author, then rerun
Safety rules
- Sequential merges only. Never merge dependency PRs in parallel, and never bypass the shared evaluator or housekeeping's default-branch verification.
- Never merge red, commented, or behind PRs.
- Never auto-merge a major version update, with or without flags — majors are always manual.
- Housekeeping is the only merge mutation owner. This skill must not invoke
gh pr merge, restate readiness logic, weaken an evaluator result, or force a merge that GitHub refuses. - Never dismiss reviews or resolve other people's review threads to make a PR look comment-clean.
- Never edit dependency manifests, lockfiles, or bot branches. This skill triages and merges; it does not write code.
dry-runperforms no mutations of any kind.
Final report
The final report is mandatory-shaped: every item below appears in every run,
and an empty item states its emptiness explicitly (write none). Keep it
scannable — bullets and short lines, one point per line, no paragraph blobs.
- Classification table: one row per dependency PR —
PR · ecosystem · delta · class. Class is one of
auto-merge,manual (major), orparked. - Merged list: the PRs merged this run, in merge order, or
none. - Parked list: every non-merged PR with its one-line reason or
recommendation, or
none. - Default-branch status: green after the final merge, or the failing checks by name.
With dry-run, the classification and parked items carry the report;
state Merged as none and the default-branch status as currently observed.
Example shape for a mixed run:
- Classification:
- #101 · npm · patch · auto-merge
- #102 · GitHub Actions · pin bump · auto-merge
- #103 · pip · minor · parked
- #104 · npm · major · manual (major)
- Merged: #101, #102 (sequential; default branch green after each)
- Parked:
- #103 — runtime minor; rerun with include-runtime-minor after review
- #104 — major; review the changelog and migration notes manually
- Default branch: green
Architecte Docker Compose
DevOps
Concoit des configurations Docker Compose optimisees.
Rapport de Post-Mortem
DevOps
Rédige des rapports post-mortem d'incidents structurés et blameless.
Créateur de Runbooks
DevOps
Crée des runbooks opérationnels clairs pour les procédures DevOps courantes.