All skills
secondsky avatar

/sap-dependency-security

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. Use when upgrading deps, configuring security policies, preventing supply chain attacks, pinning SAP MCP servers, or reviewing SAP CAP/UI5/Fiori/HANA/Datasphere/SAC/BTP/ABAP dependency workflows.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-dependency-security

This session only. Nothing lands on disk.

referencestesting-strategy.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Testing Strategy for Dependency Upgrades

Comprehensive testing approaches to validate dependency upgrades at every level.

Testing Pyramid

        E2E Tests
       /          \
    Integration Tests
    /                \
  Unit Tests
  /                    \
Static Analysis (tsc, lint)

Run from bottom to top after each upgrade.

Level 1: Static Analysis

# TypeScript type-check (fastest feedback)
bunx tsc --noEmit

# Lint
bun run lint

# Check bundle (size impact)
bun run build

Level 2: Unit Tests

# Run all unit tests
bun test

# Watch mode during upgrade
bun test --watch

# Specific test file
bun test src/components/Button.test.tsx

After upgrading, check for:

  • Type errors from API changes
  • Assertion failures from behavior changes
  • Missing exports from package restructuring

Level 3: Integration Tests

describe('Dependency Compatibility', () => {
  it('should have matching React versions', () => {
    const reactVersion = require('react/package.json').version;
    const reactDomVersion = require('react-dom/package.json').version;
    expect(reactVersion).toBe(reactDomVersion);
  });

  it('should render without crashing', () => {
    const { container } = render(<App />);
    expect(container).toBeTruthy();
  });

  it('should handle navigation', () => {
    render(<App />);
    fireEvent.click(screen.getByText('Navigate'));
    expect(screen.getByText('New Page')).toBeInTheDocument();
  });
});

Level 4: Visual Regression Tests

describe('Visual Regression', () => {
  it('should match snapshot', () => {
    const { container } = render(<Component />);
    expect(container.firstChild).toMatchSnapshot();
  });

  it('should match visual baseline', () => {
    render(<Dashboard />);
    // Compare screenshot against baseline
    cy.compareSnapshot('dashboard');
  });
});

After UI library upgrades, always check:

  • Snapshot diffs
  • Color/font changes
  • Layout shifts
  • Responsive breakpoints

Level 5: E2E Tests

// cypress/e2e/app.cy.js
describe('E2E Smoke Tests', () => {
  it('should load the app', () => {
    cy.visit('/');
    cy.get('[data-testid="app"]').should('exist');
  });

  it('should complete auth flow', () => {
    cy.visit('/login');
    cy.get('input[name="email"]').type('user@example.com');
    cy.get('button[type="submit"]').click();
    cy.url().should('include', '/dashboard');
  });

  it('should handle API errors gracefully', () => {
    cy.intercept('GET', '/api/data', { statusCode: 500 });
    cy.visit('/dashboard');
    cy.get('[data-testid="error-message"]').should('be.visible');
  });
});

Bundle Analysis

# Compare bundle sizes before and after upgrade
bun run build

# Analyze bundle composition
bunx bundle-analyzer dist/index.js

# Check for unexpected bundle size increases
# Before upgrade: note the bundle size
# After upgrade: compare and investigate increases > 5%

Performance Testing

# Run Lighthouse CI
bunx @lhci/cli autorun

# Check Core Web Vitals
# - LCP: Largest Contentful Paint
# - FID: First Input Delay
# - CLS: Cumulative Layout Shift

Upgrade Test Matrix

Test Type When to Run Failure Indicates
Type-check After every package Breaking API changes
Unit tests After every package Behavior changes
Integration After framework upgrades Compatibility issues
Visual regression After UI library upgrades Visual breaking changes
E2E After major upgrades User flow breakage
Bundle analysis After any upgrade Size regression
Performance After major upgrades Performance regression

CI Integration

# .github/workflows/upgrade-validation.yml
name: Upgrade Validation
on: [push, pull_request]
jobs:
  validate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: oven-sh/setup-bun@v2
      - run: bun install --frozen-lockfile
      - run: bunx tsc --noEmit
      - run: bun run lint
      - run: bun test
      - run: bun run build
      - run: bun run test:e2e

Source: SKILL.md on GitHub

1 alert1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a comprehensive framework for SAP dependency security, focusing on supply chain protection, lockfile hardening, and secure upgrade orchestration. It promotes industry best practices such as cooldown periods for new package releases, blocking post-install scripts, and using dedicated secrets management tools to avoid plaintext environment variables. The skill is well-documented, uses established security tools, and includes specific policies for hardening SAP-related MCP servers.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: CRITICAL · 2 issues

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2026-06-14",
  "known_issues": []
}

README badge

README badge for secondsky/sap-skills/sap-dependency-security