Skip to content

feat(skills): cat-deps meta family (python, node, actions) - #63

Open
fivepanelhat wants to merge 1 commit into
mainfrom
cat/deps-skills
Open

feat(skills): cat-deps meta family (python, node, actions)#63
fivepanelhat wants to merge 1 commit into
mainfrom
cat/deps-skills

Conversation

@fivepanelhat

Copy link
Copy Markdown
Owner

Why

Dependency work was scattered across build-ci-hygiene (Dependabot presence), secops-ci-estate-scan (audits), and ad-hoc upgrades. There was no meta policy or per-ecosystem skill family for Python, Node, and GitHub Actions deps under CAT governance.

What changed

Skill Role
skills/cat-deps Meta — estate policy, routing, maturity, HITL for majors
skills/cat-deps-python pip/uv/pyproject, pip-audit, upgrade sequence
skills/cat-deps-node npm lockfile, npm audit, Next build gate
skills/cat-deps-actions Action pins, workflow permissions, Actions Dependabot

All include optional harness contract fields. Composes with cat-code-quality, cat-pr-ship, secops-ci-estate-scan, build-ci-hygiene.

Claim / HITL notes

  • Policy skills only — no automatic upgrades applied in this PR
  • Major bumps and network-side-effect deps remain L2
  • Local-first bias: no new phone-home runtime deps without justification

Test plan

  • Four skill directories present under skills/
  • Frontmatter names match directories
  • Meta routing table points at real sibling skills
  • No application runtime code changed

Follow-ups

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant