Files
setup-uv/.agents/skills/dependabot-pr-rollup/SKILL.md
T
Kevin StillhammerandGitHub 4f6036f71c
test / test-with-explicit-token (push) Failing after 34s
test / test-setup-cache-requirements-txt (push) Failing after 26s
test / test-setup-cache-dependency-glob (push) Failing after 26s
test / test-restore-cache-requirements-txt (push) Skipped
test / test-restore-cache-dependency-glob (push) Skipped
test / test-setup-cache-restore-cache-false (push) Failing after 27s
test / test-restore-cache-restore-cache-false (push) Skipped
test / lint (push) Failing after 6m9s
test / test-specific-version (map[expected-version:0.3.2 version-input:0.3.2]) (push) Failing after 44s
test / test-version-file-version (map[expected-version:0.6.17 version-file:__tests__/fixtures/uv-in-requirements-txt-project/requirements.txt]) (push) Failing after 26s
test / test-version-file-version (map[expected-version:0.8.3 version-file:__tests__/fixtures/uv-in-requirements-hash-txt-project/requirements.txt]) (push) Failing after 22s
test / test-malformed-pyproject-file-fallback (push) Failing after 27s
test / test-python-version (ubuntu-latest) (push) Failing after 34s
test / test-cache-local-cache-disabled (push) Failing after 28s
test / test-cache-local-cache-disabled-but-explicit-path (push) Failing after 29s
test / test-custom-manifest-file (push) Failing after 30s
test / test-download-from-astral-mirror-false (push) Failing after 28s
test / test-no-python-version (push) Failing after 34s
test / test-specific-version (map[expected-version:0.3.0 version-input:0.3.0]) (push) Failing after 44s
test / test-latest-version (latest) (push) Failing after 45s
test / test-specific-version (map[expected-version:0.1.45 resolution-strategy:highest version-input:>=0.1,<0.2]) (push) Failing after 50s
test / test-specific-version (map[expected-version:0.4.25 resolution-strategy:lowest version-input:>=0.4.25,<0.5]) (push) Failing after 55s
test / test-specific-version (map[expected-version:0.4.30 version-input:>=0.4.25,<0.5]) (push) Failing after 57s
test / test-specific-version (map[expected-version:0.1.0 resolution-strategy:lowest version-input:>=0.1.0,<0.2]) (push) Failing after 58s
test / test-specific-version (map[expected-version:0.4.25 resolution-strategy:lowest version-input:>=0.4.25]) (push) Failing after 58s
test / test-uv-no-modify-path (push) Failing after 59s
test / test-default-version (ubuntu-latest) (push) Failing after 1m0s
test / test-from-working-directory-version (map[expected-version:0.5.14 working-directory:__tests__/fixtures/pyproject-toml-project]) (push) Failing after 1m0s
test / test-specific-version (map[expected-version:0.3.5 version-input:0.3]) (push) Failing after 1m3s
test / test-tool-versions-python-version (push) Failing after 20s
test / test-uvx (push) Failing after 33s
test / test-tool-install (ubuntu-latest) (push) Failing after 35s
test / test-musl (push) Failing after 31s
test / test-setup-cache-save-cache-false (push) Failing after 27s
test / test-restore-cache-save-cache-false (push) Skipped
test / test-cache-prune-force (push) Failing after 26s
test / test-cache-python-missing-managed-install-dir (push) Failing after 28s
test / test-cache-dir-from-file (push) Failing after 32s
test / test-python-install-dir (map[expected-python-dir:/home/runner/work/_temp/uv-python-dir os:ubuntu-latest]) (push) Failing after 29s
test / test-checksum (map[checksum:4d9279ad5ca596b1e2d703901d508430eb07564dc4d8837de9e2fca9c90f8ecd os:ubuntu-latest]) (push) Failing after 33s
test / test-activate-environment (ubuntu-latest) (push) Failing after 36s
test / test-activate-environment-custom-path (ubuntu-latest) (push) Failing after 38s
test / test-debian-unstable (push) Failing after 33s
test / test-activate-environment-no-project (push) Failing after 42s
test / test-setup-cache (false, ubuntu-latest) (push) Failing after 33s
test / test-setup-cache (auto, ubuntu-latest) (push) Failing after 37s
test / test-setup-cache (true, ubuntu-latest) (push) Failing after 25s
test / test-cache-key-os-version (ubuntu-22.04, ubuntu-22.04) (push) Failing after 43s
test / test-absolute-path (push) Failing after 33s
test / test-act (push) Failing after 26s
test / test-relative-path (push) Failing after 39s
test / test-workflow-run (push) Failing after 27s
test / test-cache-python-installs (push) Failing after 34s
test / test-restore-python-installs (push) Skipped
test / validate-typings (push) Successful in 34s
test / test-specific-version (map[expected-version:0.3.5 version-input:0.3.x]) (push) Failing after 1m2s
test / test-latest-version (>=0.8) (push) Failing after 1m3s
test / test-from-working-directory-version (map[expected-version:0.5.15 working-directory:__tests__/fixtures/uv-toml-project]) (push) Failing after 25s
test / test-version-file-version (map[expected-version:0.5.15 version-file:__tests__/fixtures/.tool-versions]) (push) Failing after 24s
test / test-cache-local (map[expected-cache-dir:/home/runner/work/_temp/setup-uv-cache os:ubuntu-latest]) (push) Failing after 28s
CodeQL / Analyze (TypeScript) (push) Failing after 14m51s
test / test-default-version (macos-14) (push) Canceled after 0s
test / test-default-version (macos-latest) (push) Canceled after 0s
test / test-default-version (windows-latest) (push) Canceled after 0s
test / test-checksum (map[checksum:a70cbfbf3bb5c08b2f84963b4f12c94e08fbb2468ba418a3bfe1066fbe9e7218 os:macos-latest]) (push) Canceled after 0s
test / test-tool-install (macos-14) (push) Canceled after 0s
test / test-tool-install (macos-latest) (push) Canceled after 0s
test / test-tool-install (windows-latest) (push) Canceled after 0s
test / test-python-version (macos-latest) (push) Canceled after 0s
test / test-python-version (windows-latest) (push) Canceled after 0s
test / test-activate-environment (macos-latest) (push) Canceled after 0s
test / test-activate-environment (windows-latest) (push) Canceled after 0s
test / test-activate-environment-custom-path (macos-latest) (push) Canceled after 0s
test / test-activate-environment-custom-path (windows-latest) (push) Canceled after 0s
test / test-cache-key-os-version (macos-14, macos-14) (push) Canceled after 0s
test / test-cache-key-os-version (macos-15, macos-15) (push) Canceled after 0s
test / test-cache-key-os-version (ubuntu-24.04, ubuntu-24.04) (push) Canceled after 0s
test / test-cache-key-os-version (windows-2022, windows-2022) (push) Canceled after 0s
test / test-cache-key-os-version (windows-2025, windows-2025) (push) Canceled after 0s
test / test-setup-cache (auto, windows-latest) (push) Canceled after 0s
test / test-setup-cache (false, windows-latest) (push) Canceled after 0s
test / test-setup-cache (true, windows-latest) (push) Canceled after 0s
test / test-restore-cache (auto, ubuntu-latest) (push) Canceled after 0s
test / test-restore-cache (auto, windows-latest) (push) Canceled after 0s
test / test-restore-cache (false, ubuntu-latest) (push) Canceled after 0s
test / test-restore-cache (false, windows-latest) (push) Canceled after 0s
test / test-restore-cache (true, ubuntu-latest) (push) Canceled after 0s
test / test-restore-cache (true, windows-latest) (push) Canceled after 0s
test / test-cache-local (map[expected-cache-dir:D:\a\_temp\setup-uv-cache os:windows-latest]) (push) Canceled after 0s
test / test-python-install-dir (map[expected-python-dir:D:\a\_temp\uv-python-dir os:windows-latest]) (push) Canceled after 0s
test / all-tests-passed (push) Canceled after 0s
Release Drafter / ✏️ Draft release (push) Canceled after 0s
Require pull requests for Dependabot rollups (#1005)
## Summary

- require the Dependabot rollup skill to commit and push validated
changes
- always create a pull request with the `dependencies` label
- report the created PR and label confirmation

## Testing

- `git diff --check`

Refs: pi-session 019ff0f1-1aee-7691-8a2c-7c708812f7b0
2026-08-11 15:18:43 +02:00

2.6 KiB

name, description, license, compatibility
name description license compatibility
dependabot-pr-rollup Find open Dependabot PRs for the current GitHub repo, compare each PR head to its base branch, replay only the net dependency changes in a fresh worktree and branch, run npm validation, then commit, push, and open a pull request labeled dependencies. Use when you want to batch or manually replicate active Dependabot updates. MIT Requires git, git worktree, gh CLI auth, npm, and a GitHub repo with an origin remote.

Dependabot PR Rollup

When to use

Use this skill when the user wants to:

  • find all open Dependabot PRs in the current repo
  • reproduce their net effect in one local branch
  • validate the result with the repo's standard npm checks
  • commit and push the validated changes, then open a PR labeled dependencies

Workflow

  1. Inspect the current checkout state, but do not reuse a dirty worktree.
  2. List open Dependabot PRs with gh pr list --state open --author app/dependabot.
  3. For each PR, collect the title, base branch, head branch, changed files, and relevant diffs.
  4. Compare each PR head against origin/<base> instead of trusting the PR title. Dependabot PRs can already be partially merged, superseded by newer versions, or have no remaining net effect.
  5. Create a new worktree and branch from origin/<base>.
  6. Reproduce only the remaining dependency changes in the new worktree.
    • Inspect package.json before editing.
    • Run npm ci --ignore-scripts before applying updates.
    • Use npm install ... --ignore-scripts for direct dependency changes so package-lock.json stays in sync.
    • When updating @biomejs/biome, also update the Biome schema URL version in biome.json to match the installed Biome version.
  7. Run npm run all.
  8. Commit the changed source, lockfile, and generated artifacts, then push the branch.
  9. Always open a pull request for the rollup and add the dependencies label to it. Pass --label dependencies to gh pr create, or add the label immediately afterward with gh pr edit --add-label dependencies.

Repo-specific notes

  • Use gh for GitHub operations.
  • Keep the user's original checkout untouched by working in a separate worktree.
  • In this repo, npm run all is the safest validation command because it runs build, check, package, and test.
  • If dependency changes affect bundled output, include the regenerated dist/ files.

Report back

Always report:

  • open Dependabot PRs found
  • which PRs required no net changes
  • new branch name
  • new worktree path
  • files changed
  • npm run all result
  • commit SHA and PR URL
  • confirmation that the PR has the dependencies label