reviewing-dependency-changes

作者: bitwarden

當 PR 的差異包含對依賴清單檔案(如 package.json、.csproj、Cargo.toml、go.mod、requirements.txt 等)的變更時,或當……

npx skills add https://github.com/bitwarden/ai-plugins --skill reviewing-dependency-changes

Reviewing Dependency Changes

Manifest File Detection

Flag this skill when any of these files appear in the diff:

  • package.json, package-lock.json
  • *.csproj, Directory.Packages.props, packages.lock.json
  • Cargo.toml, Cargo.lock
  • go.mod, go.sum
  • requirements.txt, pyproject.toml, poetry.lock
  • Gemfile, Gemfile.lock

Area 1: New Dependencies

When a PR adds a dependency that was not previously in the codebase, Bitwarden's Dependency Review and Approval process requires AppSec review and approval before integration. This applies to all new dependencies — production, dev, and test.

The submitter must provide the package name/version, ecosystem, justification, scope, affected products, and what it replaces. A security engineer creates a VULN task in Jira and evaluates the dependency across security (known CVEs, exploitability), license compatibility (permissive licenses like MIT/Apache-2.0 are acceptable; copyleft licenses like GPL/AGPL are flagged), maintenance health (active maintainers, recent releases, security policy), supply chain risk (typosquatting, ownership changes, obfuscated install scripts), and transitive dependencies before rendering an approval decision.

What to Check

  1. Is this a net-new dependency (not already present in the codebase)?
  2. Does the PR description contain an approval signal indicating the process was followed?

Approval Signals

Evidence that the dependency approval process was followed:

  • PR description references a VULN task (e.g., VULN-1234)
  • PR description explicitly mentions AppSec approval or the dependency review process

Severity

When emitting a finding that references the Dependency Review and Approval process, always link the process name to https://bitwarden.atlassian.net/wiki/spaces/APPSEC/pages/2774466657/Dependency+Review+and+Approval so the posted review comment points reviewers to the canonical documentation.

  • No approval signal found → ⚠️ IMPORTANT: New dependency <package> added. Bitwarden requires AppSec approval before introducing new dependencies. The submitter should reach out to the AppSec team to initiate the Dependency Review and Approval process.
  • Unclear whether approval was obtained → ❓ QUESTION: Was AppSec approval obtained for the new <package> dependency?

What NOT to Flag

  • Dependencies that already exist in the codebase (version updates are not new dependencies)
  • Dependencies added by Renovate/Dependabot as transitive dependency updates (these are part of Stage 5 monitoring for existing approved dependencies)

Area 2: Major Version Bumps

A major version bump (e.g., v2 → v3) may introduce breaking changes that affect Bitwarden's codebase.

What to Check

  1. Is this a SemVer major version change?
  2. Does the PR description discuss breaking changes or migration steps?

Severity

  • Major bump without migration discussion → ❓ QUESTION: This bumps <package> from vX to vY (major). Were breaking changes evaluated?
  • Version downgrade → ⚠️ IMPORTANT: <package> is being downgraded from vX to vY. This is unusual and may reintroduce resolved vulnerabilities.

Area 3: Lock File Hygiene

Lock files ensure reproducible builds. Inconsistencies between manifests and lock files are a build reliability and security concern.

What to Check

ScenarioFinding
Manifest changed, lock file not updated⚠️ IMPORTANT: Lock file not updated to reflect manifest changes
Lock file changed, no manifest change❓ QUESTION: Lock file changed without a corresponding manifest change — was this intentional (e.g., npm audit fix)?
Lock file deleted⚠️ IMPORTANT: Lock file removal breaks reproducible builds

What NOT to Flag

  • Large lock file diffs from a small manifest change — this is normal behavior. Lock files can change significantly from a single dependency addition or version bump.
  • Lock file-only changes that accompany a clear manifest change in the same PR.

Area 4: Automated Dependency PRs

Renovate and Dependabot PRs are part of Bitwarden's Stage 5 (Monitoring) process. These automated updates to existing approved dependencies require different review treatment.

How to Detect

  • PR author: renovate[bot], dependabot[bot], or similar bot accounts
  • PR title pattern: "Update ...", "Bump ...", "chore(deps): ..."

Review Guidance

ScenarioAction
Minor/patch update to existing dependencyNo approval-process finding needed. Focus on lock file hygiene and CI status.
Major version bump from botFlag per Area 2 — major bumps warrant human review regardless of source.
Bot PR introduces a net-new dependencyFlag per Area 1 — new dependencies require the approval process regardless of source.

Area 5: Dependency Removal

When a dependency is removed from a manifest, verify the removal is complete.

What to Check

  1. Are there remaining code references to the removed package?
    • JavaScript/TypeScript: import ... from '<package>', require('<package>')
    • C#/.NET: using <namespace>, references in other .csproj files
    • Rust: use <crate>::, extern crate <crate>
    • Python: import <package>, from <package> import
  2. Are there references in build or infrastructure files?
    • Dockerfile, docker-compose.yml
    • CI workflow files (.github/workflows/*.yml)
    • Build scripts, Makefile, task runners

Severity

  • Dead imports or references remain → ♻️ DEBT: <package> removed from manifest but still referenced in code.

來自 bitwarden 的更多技能

figma-to-angular
bitwarden
此技能可將 Figma 設計規格轉換為 Bitwarden Clients 單一儲存庫中,具備 Storybook 故事的完整 Angular 元件。輸出結果應在視覺上符合設計,同時遵循所有程式碼庫慣例。
force-multiplier
bitwarden
將單一意圖同時套用於多個目標——例如 Bitwarden 生態系中的一組儲存庫,或單一 monorepo 內的多個專案——以 N 個一致的操作來執行,…
analyzing-git-sessions
bitwarden
分析指定時間範圍或提交範圍內的 Git 提交與變更,提供結構化摘要,適用於程式碼審查、回顧會議、工作日誌或工作階段…
coordinating-cross-team-breakdown
bitwarden
協調跨團隊審查與簽核 Bitwarden 技術分解。用於識別受影響團隊、建立第三部分簽核表格、追蹤…
assessing-jira-issue-relevance
bitwarden
當使用者提供單一Jira議題金鑰,並詢問該議題是否仍相關、仍適用、仍待處理、仍是錯誤、已修復,或可否……時使用。
assessing-test-coverage
bitwarden
用於判斷特定變更(PR、Jira key、Tech Breakdown 文件、Testmo CSV、變更路徑或具名……)已存在哪些測試覆蓋範圍時使用。
retrospecting
bitwarden
對 Claude Code 工作階段進行全面分析,檢視 Git 歷史記錄、對話日誌、程式碼變更,並收集使用者回饋以產生…
reviewing-incremental-changes
bitwarden
在重新審視已有評論的PR,或回應開發者在初次審查後的變更時,使用此技能。適用於存在PR討論串或…的情況。