dependabot-configuration skill package
This package helps agents create and review GitHub Dependabot configuration for future projects.
Structure
SKILL.mdcontains the operating guidance, defaults, validation workflow, and output contract.templates/dependabot-greenfield.ymlis a safe starting point for common application and infrastructure ecosystems.templates/zizmor-workflow.ymladds a GitHub Actions security check for Dependabot and workflow files.
Validation
Use repository-level validation after changes:
apm compile --validate
npx markdownlint-cli2 ".apm/skills/dependabot-configuration/**/*.md"Currency note
Dependabot and zizmor both change quickly. Re-check GitHub Docs, Dependabot Core releases, and the zizmor audit reference before hardcoding package ecosystems, registry types, group syntax, or audit names.