e-volv

Security playbook

DependencyBump

Weekly PRs that update dependencies to their latest in-range minor and patch versions.

On a weekly schedule, updates a repository's dependencies to their latest in-range (minor/patch) versions using the project's own package manager, regenerates the lockfile, and opens a single pull request with a summary of what changed. Holds back major (breaking) upgrades and lists them for manual review. Requires the target repository to be set on the Clone step and an execution environment with the relevant toolchain (sandbox mode).

Identifier
dependency-bump
Version
1.0.1
Steps
3
Triggers
1
  • dependencies
  • maintenance
  • automated
  • scheduled
  • security

When it runs

Scheduleschedule.weekly
Schedule
Every Monday at 09:00 UTC 0 9 * * 1
Timezone
UTC

The pipeline

The graph below is the one the workflow opens with in the builder — same steps, same layout, drawn on the same canvas. The run playing through it is a simulation; the branches and conditions are real.

  1. 01
    Weekly Schedule (Mon 09:00 UTC)trigger

    The event that starts the run.

  2. 02
    Clone Repository ⚠️ SET YOUR REPOgit.clone

    Shallow-clones the repository at the right ref.

  3. 03
    Update Dependencies & Open PRagent.run

    One agent works the task with its toolkit.

The agent

Dependency Maintainer

Base type
Senior Developer
Temperature
0.1
Max iterations
40
Tools
9

Git provider · 4

  • list_pull_requestsList Pull Requests · read
  • create_branchCreate Branch · write
  • create_or_update_fileCreate or Update File · write
  • create_pull_requestCreate Pull Request · write

Filesystem · 2

  • list_dirList Directory · read
  • read_fileRead File · read

Code search · 1

  • code_searchCode Search · read

Terminal · 1

  • run_terminal_cmdRun Terminal Command · write

Status · 1

  • update_statusUpdate Status · write