CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. secondsky
  4. /
  5. claude-skills
  6. /
  7. Dependency Upgrade

Dependency Upgrade

Editor's Note

This handles the full lifecycle of upgrading dependencies with supply chain security baked in: cooldown periods to let new packages age before you install them, post-install script blocking to prevent arbitrary code execution, and lockfile validation to catch injection attacks. It supports npm, Bun, pnpm, Yarn, and Deno with specific hardening configs for each. You can run it in default mode for instant opinionated setup (7-day cooldown, scripts blocked, Dependabot configured) or go interactive to customize everything from automerge policies to Socket CLI integration. It's built around the reality that supply chain attacks happen fast and most teams don't have good defenses in place until after an incident.

Install

npx skills add https://github.com/secondsky/claude-skills --skill dependency-upgrade
Votes
0
Installs222
GitHub Stars162
Categories
Security
First SeenJun 3, 2026
View on GitHub

Comments

Login to comment

Related Security Skills

View all →
security-audit-scanner

tbartel74/Vigil-Code

0
8
Automated security scanning for Vigil Guard v2.0.0. Use for OWASP Top 10 checks, TruffleHog secret detection, npm/pip vulnerability scanning, 3-branch service security, heuristics-service audit, and CI/CD security pipelines.
permission-auditor

useai-pro/openclaw-skills-security

0
377
58
permission auditor
supabase-audit-auth-config

yoanbernabeu/supabase-pentest-skills

0
237
43
supabase audit auth config
supabase-audit-auth-users

yoanbernabeu/supabase-pentest-skills

0
208
43
supabase audit auth users
supabase-audit-auth-signup

yoanbernabeu/supabase-pentest-skills

0
205
43
supabase audit auth signup
supabase-audit-authenticated

yoanbernabeu/supabase-pentest-skills

0
182
43
supabase audit authenticated