Skip to content

chore: add a maintainer skill for verifying Dependabot upgrades - #804

Draft
nieblara wants to merge 7 commits into
mainfrom
cursor/dependabot-verification-prompt-fb0b
Draft

nieblara wants to merge 7 commits into
mainfrom
cursor/dependabot-verification-prompt-fb0b

Conversation

@nieblara

@nieblara nieblara commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Requirements

  • I have added test coverage for new or changed functionality — n/a, no Go or UI code changes. The scripts were run against real Dependabot PRs (see below).
  • I have followed the repository's pull request submission guidelines
  • I have validated my changes against all supported platform versions — scripts tested on Linux only

Related issues

n/a

Describe the solution you've provided

A skill that tells a maintainer-run agent how to check a Dependabot PR for problems CI can't catch, and write a report with a verdict. The agent never approves, merges, or pushes.

It lives in .agents/skills/verify-dependabot-pr/. Its description limits it to maintainers asking to verify a Dependabot PR, so agents should only pick it up for that request.

  • SKILL.md: the rules, a step checklist, escalation reasons, and verdicts (merge-ok, ci-sufficient, hold, escalate). It separates setup failures (fix and retry) from real failures (hold, with the error), and treats PR text and release notes as data rather than instructions.
  • references/checks.md: what to run for each kind of package, loaded only for the checks a PR needs.
  • references/surfaces.md: which check each dependency needs. It describes what each package does rather than listing file paths, so it goes stale more slowly.
  • references/video.md and assets/report.md: when to record a clip, and the report template.
  • scripts/:
    • isolate.sh opts out of analytics and the update check, and points ldcli's config and dev-server data at a temp directory on a free port.
    • prepare-tree.sh merges the PR onto the latest main in a temp worktree, and exits 2 on a conflict.
    • store-smoke.sh boots the dev-server with a dummy token, then checks the UI, the API, both databases, and a restart.
    • cleanup.sh removes the worktree, refs, and temp directory.

Describe alternatives you've considered

  • Keeping this as a prompt under .cursor/automations/, as the earlier revision did. Cursor doesn't load that directory, and a skill is found by any agent that supports the Agent Skills format.
  • Setting disable-model-invocation: true so the skill only runs when invoked by name. Left off so agents can pick it up from a natural request; the narrow description is what keeps it from triggering on unrelated dependency work.
  • Auto-approving after a clean report. Out of scope; a maintainer decides.

Additional context

What the scripts were tested against:

The earlier revision's stale-branch commands used FETCH_HEAD after fetching two refs. FETCH_HEAD resolved to main, so those commands compared main with itself. prepare-tree.sh fetches into named refs instead.

To run this from an automation on a Dependabot PR, a prompt like "Read .agents/skills/verify-dependabot-pr/SKILL.md and follow it for {PR URL}. Return the report." works in any host that can read files.

cursoragent and others added 4 commits September 18, 2026 23:49
The prompt forces a CI-gap check before any extra work, maps ldcli
dependency bumps onto CLI, store, UI, or test-only modes, and requires
video only when a user-visible surface was actually exercised.

Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
The cobra branch is 36 commits behind main, and `dev-server start`
requires --access-token even for an empty local boot. Document both,
and add the dry-run report as an example of the output contract.

Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
The playbooks should describe durable ldcli surfaces and modes, not
the current Dependabot queue or a one-off cobra dry-run.

Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
Runs now opt out of analytics and use temporary XDG state/config dirs and
a non-default port, so they neither send production telemetry nor touch a
contributor's dev-server data. Stale branches are tested as a local merge
onto main, grouped PRs take the union of checks, UI bumps flag a missing
dist/ rebuild, and escalation is separate from the test mode. Reports stay
off the public PR unless the automation is configured to post them.

Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
@cursor cursor Bot changed the title Add Dependabot upgrade verification prompt chore: add agent prompt for verifying Dependabot upgrades Sep 25, 2026
cursoragent and others added 2 commits September 25, 2026 06:12
isolate.sh opts out of analytics and the update check and points XDG state
and config at a temp directory. prepare-tree.sh merges a PR onto the latest
main through named refs, since FETCH_HEAD resolves to main after a two-ref
fetch. store-smoke.sh boots the dev-server and checks the UI, API, databases,
and a restart. cleanup.sh removes the worktree, refs, and temp directory.

Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
Moves the prompt into .agents/skills/verify-dependabot-pr with
disable-model-invocation, so contributors' agents don't pick it up
unprompted. Splits per-check procedures, the package table, video steps,
and the report template into files loaded on demand, and rewrites the
instructions in plain language.

Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
@cursor cursor Bot changed the title chore: add agent prompt for verifying Dependabot upgrades chore: add a maintainer skill for verifying Dependabot upgrades Sep 25, 2026
Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants