dependabot-pr - Investigate and process Dependabot pull requests
Investigates, validates, and merges Dependabot pull requests sequentially with user confirmation at each phase.
Tags
Updated: 2026-10-07Capabilities
Typical Inputs
Typical Outputs
What this skill does
- List open Dependabot PRs
- Review dependency changes
- Assess dependency impact
- Check release notes
- Run local validation
- Run security scans
- Merge or skip PRs
- Report processing results
Inputs
- GitHub repository
- Open Dependabot pull requests
- Dependency configuration
- Local working environment
- User merge decisions
- Release notes
- Changelog files
Outputs
- Pull request inventory
- Impact assessment reports
- Validation results
- Merged pull requests
- Skipped pull requests
- Completion report
Requirements
- Installed gh CLI
- Authenticated GitHub access
- Configured git
- Remote repository access
- Prepared Rails test environment
- Working bundler-audit command
- Available defined sub-agents
