PlugMyPlugin
← Browse

dependency-upgrade

secondsky ★ 220

This skill provides a comprehensive workflow for securely upgrading dependencies across npm, Bun, pnpm, and Yarn while preventing supply chain attacks through cooldown periods, post-install script hardening, lockfile validation, and staged rollouts. It integrates with tools like lockfile-lint, npq, and Socket Firewall to audit packages before installation and detect injection attacks.

DevOps Security free prompt pack

Install

> /plugin marketplace add secondsky/claude-skills/tree/HEAD/plugins/dependency-upgrade
> /plugin install dependency-upgrade

Source: https://github.com/secondsky/claude-skills/tree/HEAD/plugins/dependency-upgrade

What it's made of

1 skill

Commands
0
Agents
0
Skills
1
MCP servers
0
Hooks
0

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
none
Talks to
nothing external detected

Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (secondsky).