All skills
lukemurraynz avatar

/dependabot-configuration

@2077a21

Create, review, and harden GitHub Dependabot configuration for new or existing repositories. Use for .github/dependabot.yml, Dependabot version updates, Dependabot security updates, grouped updates, multi-ecosystem groups, private registries, Dependabot secrets, GitHub Actions updates, Dependabot automation workflows, and zizmor validation of Dependabot and workflow supply-chain hygiene.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/dependabot-configuration

This session only. Nothing lands on disk.

README.md

≈221 tokens on demand. Your agent reads this file only when SKILL.md points to it.

dependabot-configuration skill package

This package helps agents create and review GitHub Dependabot configuration for future projects.

Structure

  • SKILL.md contains the operating guidance, defaults, validation workflow, and output contract.
  • templates/dependabot-greenfield.yml is a safe starting point for common application and infrastructure ecosystems.
  • templates/zizmor-workflow.yml adds a GitHub Actions security check for Dependabot and workflow files.

Validation

Use repository-level validation after changes:

apm compile --validate
npx markdownlint-cli2 ".apm/skills/dependabot-configuration/**/*.md"

Currency note

Dependabot and zizmor both change quickly. Re-check GitHub Docs, Dependabot Core releases, and the zizmor audit reference before hardcoding package ecosystems, registry types, group syntax, or audit names.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The dependabot-configuration skill helps agents generate and audit GitHub Dependabot configuration files using industry-standard security tools like zizmor. It incorporates best practices such as least-privilege permissions, OIDC for registry access, and SHA pinning for GitHub Actions, and it refers users to official documentation for security verification.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2077a21. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
metadata
{
  "last_verified": "2026-06-26"
}
Other metadata
compatibility
GitHub Dependabot configuration version 2, GitHub Actions, GitHub Advanced Security code scanning where available, and zizmor 1.x. Verify current GitHub Docs and zizmor docs before writing production configuration.

README badge

README badge for lukemurraynz/hve-agent-skills/dependabot-configuration