Remediates GitHub Dependabot alerts for mflux in one dependency-security change. Use when auditing, clamping, or upgrading Python dependencies in pyproject.toml and uv.lock, or when validating whether a branch will close Dependabot findings before opening a PR.
73
90%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Resolve actionable Dependabot alerts with the smallest compatible dependency update and prove the local lock is outside every reported vulnerable range.
gh api as the source of truth for open alerts in mflux-community/mflux.pyproject.toml and uv.lock unless compatibility requires source changes.Confirm the current branch and working tree before editing.
Fetch all open Dependabot alerts, following pagination:
gh api --method GET --paginate \
-H "Accept: application/vnd.github+json" \
repos/mflux-community/mflux/dependabot/alerts \
-f state=openGroup alerts by manifest, package, severity, vulnerable range, and first patched version. Distinguish direct requirements from transitive lock entries.
Inspect pyproject.toml, uv.lock, supported Python versions, and platform markers before choosing a fix.
Prefer, in order:
Use one requirement when a release supports the full project matrix. Do not introduce overlapping marker-specific requirements without evidence that they are necessary.
Regenerate the lock with targeted upgrades:
uv lock --upgrade-package <package> [--upgrade-package <package> ...]Review the lock diff. Explain large platform-specific resolver changes, especially PyTorch CUDA package transitions, rather than assuming they are accidental.
Do not infer alert closure solely from package names or Dependabot's hosted UI.
Run lock and advisory checks:
uv lock --check
uv audit --preview-features audit-commandParse every resolved version in uv.lock and compare it with every open alert's security_vulnerability.vulnerable_version_range. Canonicalize names with packaging.utils.canonicalize_name and use packaging.specifiers.SpecifierSet so matching follows Python package name and version semantics.
Confirm that each alert is resolved by either:
Run Dependabot Core against the local checkout before opening a PR:
tmp_dir="$(mktemp -d)"
trap 'rm -rf "$tmp_dir"' EXIT
job="$tmp_dir/job.yml"
output="$tmp_dir/output.yml"
# Build the security job at "$job" before running these commands.
dependabot graph uv mflux-community/mflux --local "$PWD"
dependabot update --local "$PWD" -f "$job" -o "$output" --pull=false --timeout 20mgraph is experimental and may return an incomplete dependency list. Both commands snapshot the directory passed to --local, including modified and untracked files, so confirm that the working tree contains only the intended updater input.
Build the temporary uv security job from the exact package names and advisory ranges returned by GitHub. Parse the YAML output rather than relying on the command's exit status:
uv run python - "$output" <<'PY'
import sys
import yaml
with open(sys.argv[1]) as output_file:
actions = {entry["type"] for entry in yaml.safe_load(output_file)["output"]}
if "mark_as_processed" not in actions:
raise SystemExit("Dependabot did not mark the job as processed")
pull_request_actions = actions & {"create_pull_request", "update_pull_request"}
if pull_request_actions:
raise SystemExit(f"Dependabot still proposes actions: {sorted(pull_request_actions)}")
PYDo not pin Dependabot CLI to one release. Verify the installed CLI exposes the commands and flags used here before running the job.
Keep temporary Dependabot job and output files outside the committed change, and remove them after verification.
If the hosted alert remains open while the local lock is already outside its vulnerable range, report it as pending or stale until GitHub rescans. Do not force an unnecessary upgrade just to change the lock entry.
Run the repository workflows after the lock is secure:
just lint
just lint-justfile
just typecheck
just test-fast
just test
just build
git diff --checkUse uv lock --upgrade --dry-run to check that a fresh universal resolution succeeds. It may report unrelated newer releases; do not add them unless they are needed for the remediation.
Report:
uv audit, and project checks;adcbe85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.