--- name: dependency-management description: "Investigate whether a dependency is actually necessary, check existing versions/conventions, minimize dependency additions, and update lockfiles deliberately." --- # Dependency Management Skill Investigate whether a dependency is actually necessary, check existing versions/conventions, minimize dependency additions, and update lockfiles deliberately. ## Subagents When you need to delegate sub‑tasks, use the `pi-subagents` skill. **Example:** To evaluate a new dependency, use a **scout** to check if the functionality exists in the standard library, another **scout** to compare versions and licensing of alternatives, and a **reviewer** to verify the lockfile update doesn't introduce transitive conflicts. *You may adapt the delegation pattern to fit the exact requirements of the codebase.* ## Process ### 1. Necessity - Can this be done with stdlib? - Is there an existing internal utility? - What's the maintenance cost? ### 2. Conventions - Check existing similar dependencies - Follow version pinning policy - Use approved registries ### 3. Minimize - Prefer fewer, well-maintained deps - Avoid transitive dependency bloat - Consider vendoring for small utils ### 4. Update - Update lockfiles atomically - Test after updates - Document breaking changes