← Browse
dependabot-audit
Machai-Kydoimos ★ 0
This plugin audits Dependabot and Renovate dependency-bump PRs by verifying artifact hashes, checking for version staleness, scanning changelogs for undisclosed fixes, and detecting behavior changes in linters and formatters—then produces an evidence-backed merge recommendation without actually merging. It comprehensively handles Python/uv.lock, GitHub Actions, and pre-commit ecosystems end-to-end, with stated boundaries for other ecosystems.
Install
> /plugin marketplace add Machai-Kydoimos/dependabot-audit
> /plugin install dependabot-audit
What it's made of
1 skill
- Commands
- 0
- Agents
- 0
- Skills
- 1
- MCP servers
- 0
- Hooks
- 0
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
- none
- Talks to
- nothing external detected
Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (Machai-Kydoimos).