Dependabot merge
Plugin with opinionated set of Claude Code agents nad skills
npx -y skills add lklimek/claudius --skill dependabot-mergeAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Bulk-process open dependabot PRs: audit each dependency, comment findings, merge if CI green, request rebase on conflicts or CI failures. Use to merge dependabot PRs, process dependency bumps, auto-merge bot PRs, or handle dependabot backlog.
SKILL.md
6.3 KB, as published. Nobody here has run it
Dependabot PR Bulk Processor
Audit, comment, and merge open dependabot PRs in a repository. Each PR gets a security review via the review-dependency skill, a comment with findings, and — if safe — a squash merge.
Argument: $ARGUMENTS — optional filter (e.g., golang, docker, npm). If empty, process all open dependabot PRs.
Prerequisites
ghsudoinstalled for write operations (pip install ghsudo)- GitHub MCP tools available (
mcp__plugin_claudius_github__*) review-dependencyskill available
Workflow
1. Discover Open Dependabot PRs
Search for open PRs authored by app/dependabot:
gh pr list --repo <owner>/<repo> --author 'app/dependabot' \
--json number,title,statusCheckRollup,mergeable --limit 50
Extract for each PR: number, title, CI status (which checks passed/failed), and mergeable state.
If $ARGUMENTS is set, filter PRs whose title contains the filter string.
2. Check for Unpushed Commits
Before spawning worktree agents:
git log @{upstream}..HEAD --oneline
If unpushed commits exist, alert the user and stop. Worktree agents fork from the remote state — unpushed local commits will be missing. If no upstream is configured, use git log origin/$(git branch --show-current)..HEAD as fallback.
3. Classify PRs
Sort PRs into three groups:
| Group | Condition | Action |
|---|---|---|
| Green | All CI checks passed + MERGEABLE | Audit, Comment, Merge |
| Red | CI failures + MERGEABLE | Audit, Comment, @dependabot rebase |
| Conflicting | CONFLICTING mergeable state | Comment conflict notice, @dependabot rebase |
Present the classification table to the user and ask for confirmation before proceeding.
4. Spawn Review Agents
For each PR, the coordinator pre-creates an isolated worktree (see grand-admiral § Worktree Isolation — the isolation flag is unreliable for run_in_background spawns) and spawns a background agent that cds into it as its FIRST action:
Agent(
mode: "bypassPermissions",
run_in_background: true,
prompt: "cd <pre-created worktree abs-path> first, then review the dependabot PR ..."
)
Set model per spawn: opus for every dependency bump — a bump pulls in third-party code and is security-sensitive by default; a passing vulnerability scan (e.g. govulncheck) is NOT evidence of low risk. ALWAYS fully investigate the bump, including the updated dependency's changed code; never downgrade to Sonnet.
Agent prompt must include ALL of:
- PR number, title, repo
<owner>/<repo> - CI status — green or red, which checks failed
- Mergeable state
- Instruction to invoke
review-dependencyskill with the PR number as argument - Instruction to post a comment with findings via
mcp__plugin_claudius_github__add_issue_comment(include attribution footer) - If Green: merge via
ghsudo gh pr merge <number> --repo <owner>/<repo> --squash - If Red or Conflicting: do NOT merge; post
@dependabot rebasecomment, then enter Rebase Watch Loop (step 5a)
Spawn all agents in a single message for maximum parallelism.
5. Collect Results and Handle Write Blocks
As agents complete, check their results. Agents may be blocked from GitHub write operations by hooks. For blocked agents:
- Post the review comment yourself using GitHub MCP
- Execute the merge, rebase request, or watch loop yourself
5a. Rebase Watch Loop
After posting @dependabot rebase, poll until the rebase lands and CI completes (or timeout).
- Record the current HEAD SHA before requesting rebase
- Poll every 60s (max 15 minutes):
gh pr view --repo <owner>/<repo> <number> --json headRefOid,statusCheckRollup,mergeable - Exit conditions:
| Condition | Action |
|---|---|
headRefOid changed + all checks SUCCESS + mergeable == MERGEABLE | Squash merge via ghsudo gh pr merge |
headRefOid changed + any check FAILURE | Report as CI Red after rebase — do NOT re-rebase |
| 15 min elapsed, HEAD unchanged | Report as Rebase Timeout |
| Merge attempt fails (race, new conflict) | Report as Merge Failed after rebase |
On successful merge, report as Merged after rebase.
6. Handle Cascading Merge Failures
After earlier PRs merge, later PRs may become unmergeable (conflicting go.sum, lock files, etc.). When a merge fails with "not mergeable":
- Post
@dependabot rebaseon the PR - Enter Rebase Watch Loop (step 5a) — same timeout and CI check logic
7. Final Report
Present a summary table:
| PR | Dependency | Audit | Action | Result |
|---|---|---|---|---|
| #NNN | pkg old->new | Safe/Risk | Merged/Rebase/Skipped | OK/MERGED_AFTER_REBASE/CI_RED/TIMEOUT/MERGE_FAILED/WARN |
Include:
- Total merged count (direct + after rebase)
- Rebase outcomes: merged after rebase, CI red after rebase, rebase timeout, merge failed after rebase
- Any PRs with security concerns (not merged)
- Note flaky tests if multiple PRs failed the same test
8. Lessons Learned
After completing all PRs, invoke claudius:lessons-learned skill if notable patterns emerged (flaky tests blocking merges, recurring merge conflicts, security concerns).
Attribution Footer
Every GitHub comment MUST end with:
<sub>🤖 Co-authored by [Claudius the Magnificent](https://github.com/lklimek/claudius) AI Agent</sub>
Safety Rules
- Never merge a PR with security concerns — comment only
- Never merge a PR with failing CI — request rebase instead
- Always get user confirmation before starting the bulk operation
- Use
ghsudofor all write operations (merge, comment) whenghalone fails with 403/404 - If
ghsudoexits with code 2 (user denied), skip that PR and move on - If
ghsudoexits with code 4 (no token), inform user to runghsudo --setup <org>