blob: 213e8489de3c11e824b4cbb5a426749cb52a0ac2 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
|
---
name: dependency-management
description: "Investigate whether a dependency is actually necessary, check existing versions/conventions, minimize dependency additions, and update lockfiles deliberately."
---
# Dependency Management Skill
Investigate whether a dependency is actually necessary, check existing versions/conventions, minimize dependency additions, and update lockfiles deliberately.
## Process
### 1. Necessity
- Can this be done with stdlib?
- Is there an existing internal utility?
- What's the maintenance cost?
### 2. Conventions
- Check existing similar dependencies
- Follow version pinning policy
- Use approved registries
### 3. Minimize
- Prefer fewer, well-maintained deps
- Avoid transitive dependency bloat
- Consider vendoring for small utils
### 4. Update
- Update lockfiles atomically
- Test after updates
- Document breaking changes
|