From 64028ddad86f2fb27c3e7ec199e03a54c020f137 Mon Sep 17 00:00:00 2001 From: ashmod Date: Wed, 30 Sep 2026 19:07:36 +0300 Subject: [PATCH 1/3] add frontmatter to dependency review agent skill --- .../SKILL.md | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) rename .agents/skills/{dependency_review_plan => dependency-review-plan}/SKILL.md (92%) diff --git a/.agents/skills/dependency_review_plan/SKILL.md b/.agents/skills/dependency-review-plan/SKILL.md similarity index 92% rename from .agents/skills/dependency_review_plan/SKILL.md rename to .agents/skills/dependency-review-plan/SKILL.md index ebc0efb107f..c4659b8b7ad 100644 --- a/.agents/skills/dependency_review_plan/SKILL.md +++ b/.agents/skills/dependency-review-plan/SKILL.md @@ -1,3 +1,8 @@ +--- +name: dependency-review-plan +description: Review open dependency update pull requests in google/osv.dev and report which need manual review, without approving or merging them. +--- + # Dependency Update Review Plan - google/osv.dev This document outlines the workflow for reviewing and managing dependency update Pull Requests in the `google/osv.dev` repository. @@ -32,4 +37,4 @@ Present the final summary report to the user. Do not execute any approval or mer Consider the following during the review process: - **API Snapshot Tests**: Monitor the `PR-api-snapshot-tests` workflow, as it is highly sensitive to transitive dependency changes. Manual review is required if it fails to ensure output formats haven't regressed. - **Go API Clients**: Expect frequent updates to `google.golang.org/api` across multiple services (vulnfeeds, indexer, tools). -- **Renovate Branch Patterns**: Use Renovate branch names (e.g., `renovate/major-docs`) as a reliable heuristic for identifying major version jumps. \ No newline at end of file +- **Renovate Branch Patterns**: Use Renovate branch names (e.g., `renovate/major-docs`) as a reliable heuristic for identifying major version jumps. From f22d3beb91feb3b2e61ba9a26511093891806596 Mon Sep 17 00:00:00 2001 From: ashmod Date: Wed, 30 Sep 2026 19:31:52 +0300 Subject: [PATCH 2/3] remove eof extra line for a cleaner diff --- .agents/skills/dependency-review-plan/SKILL.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.agents/skills/dependency-review-plan/SKILL.md b/.agents/skills/dependency-review-plan/SKILL.md index c4659b8b7ad..f8b3273ab3b 100644 --- a/.agents/skills/dependency-review-plan/SKILL.md +++ b/.agents/skills/dependency-review-plan/SKILL.md @@ -37,4 +37,4 @@ Present the final summary report to the user. Do not execute any approval or mer Consider the following during the review process: - **API Snapshot Tests**: Monitor the `PR-api-snapshot-tests` workflow, as it is highly sensitive to transitive dependency changes. Manual review is required if it fails to ensure output formats haven't regressed. - **Go API Clients**: Expect frequent updates to `google.golang.org/api` across multiple services (vulnfeeds, indexer, tools). -- **Renovate Branch Patterns**: Use Renovate branch names (e.g., `renovate/major-docs`) as a reliable heuristic for identifying major version jumps. +- **Renovate Branch Patterns**: Use Renovate branch names (e.g., `renovate/major-docs`) as a reliable heuristic for identifying major version jumps. \ No newline at end of file From e29144c1c0b3ba2196899dd7cf1e95041d64acfa Mon Sep 17 00:00:00 2001 From: Shehab <127568346+ashmod@users.noreply.github.com> Date: Thu, 1 Oct 2026 06:15:53 +0300 Subject: [PATCH 3/3] delete dependency review skill --- .../skills/dependency-review-plan/SKILL.md | 40 ------------------- 1 file changed, 40 deletions(-) delete mode 100644 .agents/skills/dependency-review-plan/SKILL.md diff --git a/.agents/skills/dependency-review-plan/SKILL.md b/.agents/skills/dependency-review-plan/SKILL.md deleted file mode 100644 index f8b3273ab3b..00000000000 --- a/.agents/skills/dependency-review-plan/SKILL.md +++ /dev/null @@ -1,40 +0,0 @@ ---- -name: dependency-review-plan -description: Review open dependency update pull requests in google/osv.dev and report which need manual review, without approving or merging them. ---- - -# Dependency Update Review Plan - google/osv.dev - -This document outlines the workflow for reviewing and managing dependency update Pull Requests in the `google/osv.dev` repository. - -## 1. Discovery & Triage -Identify all open dependency updates. -- **Action**: Use `gh pr list` to fetch PRs with the `dependencies` label. -- **Criteria**: Filter for `state:open`. - -## 2. Analysis & Review -Execute the analysis process using the deterministic Python script: `tools/review_dependency_prs.py`. Perform the following checks: -- **CI/CD Status**: Analyze structured JSON output from `gh pr view --json statusCheckRollup` to reliably identify pending or failing checks (ignoring `SUCCESS`, `SKIPPED`, and `NEUTRAL`). -- **Change Scope**: Use `gh pr diff --name-only` to ensure modifications are restricted to expected files: - - Dependency manifests (`go.mod`, `poetry.lock`, `package.json`, etc.) - - Submodule updates - - Dockerfile and Terraform version updates - - GitHub Actions workflow updates (`.github/workflows/`) -- **Version Analysis**: Inspect the PR's branch name (e.g., looking for `renovate/major-...`) and PR title to identify major semantic version jumps. - -## 3. Reporting -Run the `tools/review_dependency_prs.py` script to generate a final summary report categorized into: -- ✅ **Ready for Submission**: Patch or Minor updates with passing CI and standard file changes. -- ⚠️ **Manual Review Required**: - - Major version upgrades (high risk of breaking changes). - - PRs with failing or pending CI checks. - - PRs modifying files outside the standard dependency manifests. - -## 4. Final Review -Present the final summary report to the user. Do not execute any approval or merge commands (e.g., `approve_dependency_prs.sh`, `gh pr review`, or `gh pr merge`). The user will use the provided report to manually trigger any necessary scripts or actions. - -## 5. Notable Observations & Learnings -Consider the following during the review process: -- **API Snapshot Tests**: Monitor the `PR-api-snapshot-tests` workflow, as it is highly sensitive to transitive dependency changes. Manual review is required if it fails to ensure output formats haven't regressed. -- **Go API Clients**: Expect frequent updates to `google.golang.org/api` across multiple services (vulnfeeds, indexer, tools). -- **Renovate Branch Patterns**: Use Renovate branch names (e.g., `renovate/major-docs`) as a reliable heuristic for identifying major version jumps. \ No newline at end of file