harnessprotocol/harness-kit · plugins/dependabot-sweep/skills/dependabot-sweep/SKILL.md

dependabot-sweep skillA

Use when the user wants to fix, address, clear, or resolve open Dependabot security/vulnerability alerts for a repository, end to end. Fetches open alerts via the gh CLI, fixes them per ecosystem (pnpm/npm overrides + lockfile regen, cargo update, pip/go/bundler), verifies with audit and frozen-lockfile installs, then branches → commits → pushes → opens a PR, and squash-merges once CI is green — escalating only when a fix carries breaking-change risk or can't be resolved. Trigger on "/dependabot

Latest version
mdr add harnessprotocol/harness-kit/dependabot-sweep@git:20260727.f61816c
Exact content
mdr add harnessprotocol/harness-kit/dependabot-sweep@sha256:1921f4edc5574066
Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_voqxjlp5g5nc5lma.svg)](https://markdownregistry.com/a/art_voqxjlp5g5nc5lma)

0 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260727.f61816c latest2026-07-27 f61816c 9,474 BA view · diff
git:20260605.7db75252026-06-05 7db7525 9,282 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.

Source

GitHub

harnessprotocol/harness-kit · 10 stars · license Apache-2.0 · pushed 2026-09-04 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_voqxjlp5g5nc5lma
GET https://markdownregistry.com/api/v1/resolve?ref=harnessprotocol/harness-kit/dependabot-sweep
GET https://markdownregistry.com/api/v1/blob/1921f4edc55740664a2b83793e41bc875c9df9c206d55b1a2c01fe07acb7936f