PlugMyPlugin
← Browse

dependabot-audit

Machai-Kydoimos ★ 0

This plugin audits Dependabot and Renovate dependency-bump PRs by verifying artifact hashes, checking for version staleness, scanning changelogs for undisclosed fixes, and detecting behavior changes in linters and formatters—then produces an evidence-backed merge recommendation without actually merging. It comprehensively handles Python/uv.lock, GitHub Actions, and pre-commit ecosystems end-to-end, with stated boundaries for other ecosystems.

Security DevOps free prompt pack

Install

> /plugin marketplace add Machai-Kydoimos/dependabot-audit
> /plugin install dependabot-audit

Source: https://github.com/Machai-Kydoimos/dependabot-audit

What it's made of

1 skill

Commands
0
Agents
0
Skills
1
MCP servers
0
Hooks
0

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
none
Talks to
nothing external detected

Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (Machai-Kydoimos).