跳到主要内容
知仓学习社ZHICANG

dependency-scanner

Comprehensive dependency scanning, inventory generation, and SBOM creation for migration readiness assessment

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,15 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Dependency Scanner Skill

Performs comprehensive dependency scanning and inventory generation for codebases, supporting migration planning and security assessments through SBOM (Software Bill of Materials) generation.

Purpose

Enable comprehensive dependency management for:

  • Direct and transitive dependency extraction
  • Dependency tree visualization
  • Version conflict detection
  • Circular dependency identification
  • License extraction and compliance
  • SBOM generation (CycloneDX, SPDX formats)

Capabilities

1. Direct/Transitive Dependency Extraction

  • Parse package manifests (package.json, pom.xml, requirements.txt, etc.)
  • Resolve full dependency trees including transitive dependencies
  • Identify version constraints and resolution results
  • Track dependency sources and registries

2. Dependency Tree Visualization

  • Generate hierarchical dependency graphs
  • Export to DOT, JSON, or Mermaid formats
  • Highlight problematic paths
  • Calculate tree depth and breadth metrics

3. Version Conflict Detection

  • Identify version conflicts in dependency trees
  • Detect peer dependency violations
  • Find incompatible version ranges
  • Suggest resolution strategies

4. Circular Dependency Identification

  • Detect circular dependency chains
  • Map dependency cycles
  • Assess impact of circular dependencies
  • Recommend breaking strategies

5. License Extraction

  • Extract license information from dependencies
  • Identify license types (MIT, Apache, GPL, etc.)
  • Flag copyleft licenses
  • Track dual-licensed packages

6. SBOM Generation

  • Generate CycloneDX format SBOMs
  • Generate SPDX format SBOMs
  • Include vulnerability references
  • Support machine-readable and human-readable outputs

Tool Integrations

This skill can leverage the following external tools when available:

| Tool | Purpose | Integration Method |

|------|---------|-------------------|

| npm/yarn/pnpm | Node.js dependencies | CLI |

| Maven | Java dependencies | CLI |

| Gradle | Java/Kotlin dependencies | CLI |

| pip/pipenv/poetry | Python dependencies | CLI |

| Bundler | Ruby dependencies | CLI |

| Cargo | Rust dependencies | CLI |

| Go Modules | Go dependencies | CLI |

| Snyk | Security scanning | CLI / API |

| OWASP Dependency-Check | Vulnerability scanning | CLI |

| Trivy | SBOM generation | MCP Server / CLI |

| Syft | SBOM generation | CLI |

Usage

Basic Scanning

# Invoke skill for dependency scanning
# The skill will auto-detect package managers and scan accordingly

# Expected inputs:
# - targetPath: Path to project root
# - scanDepth: 'direct' | 'transitive' | 'full'
# - outputFormat: 'json' | 'tree' | 'sbom-cyclonedx' | 'sbom-spdx'
# - includeLicenses: boolean

Scanning Workflow

  1. Detection Phase
  • Identify package managers in use
  • Locate manifest files
  • Check for lock files
  1. Extraction Phase
  • Parse manifest files
  • Resolve dependency trees
  • Extract version information
  1. Analysis Phase
  • Detect conflicts
  • Identify circular dependencies
  • Extract licenses
  1. Output Generation
  • Generate inventory reports
  • Create SBOMs if requested
  • Produce visualization artifacts

Output Schema

{
  "scanId": "string",
  "timestamp": "ISO8601",
  "target": {
    "path": "string",
    "packageManagers": ["string"],
    "manifestFiles": ["string"]
  },
  "summary": {
    "totalDependencies": "number",
    "directDependencies": "number",
    "transitiveDependencies": "number",
    "uniquePackages": "number",
    "treeDepth": "number"
  },
  "dependencies": [
    {
      "name": "string",
      "version": "string",
      "type": "direct|transitive",
      "parent": "string|null",
      "license": "string",
      "repository": "string",
      "depth": "number"
    }
  ],
  "conflicts": [
    {
      "package": "string",
      "versions": ["string"],
      "sources": ["string"],
      "recommendation": "string"
    }
  ],
  "circularDependencies": [
    {
      "chain": ["string"],
      "severity": "high|medium|low"
    }
  ],
  "licenses": {
    "summary": {
      "MIT": "number",
      "Apache-2.0": "number",
      "GPL-3.0": "number"
    },
    "copyleft": ["string"],
    "unknown": ["string"]
  },
  "sbom": {
    "format": "cyclonedx|spdx",
    "version": "string",
    "path": "string"
  }
}

Integration with Migration Processes

This skill integrates with the following Code Migration/Modernization processes:

  • dependency-analysis-updates: Primary tool for dependency assessment
  • legacy-codebase-assessment: Dependency inventory for legacy systems
  • framework-upgrade: Compatibility analysis for upgrades
  • cloud-migration: Dependency portability assessment

Configuration

Skill Configuration File

Create .dependency-scanner.json in the project root:

{
  "packageManagers": ["auto"],
  "excludePaths": ["node_modules", ".git"],
  "scanDepth": "full",
  "includeDev": true,
  "includeOptional": false,
  "licensePolicy": {
    "allowed": ["MIT", "Apache-2.0", "BSD-3-Clause", "ISC"],
    "flagged": ["GPL-3.0", "AGPL-3.0"],
    "blocked": []
  },
  "sbomConfig": {
    "format": "cyclonedx",
    "version": "1.5",
    "includeVulnerabilities": true
  }
}

MCP Server Integration

When Trivy SBOM Generator MCP Server is available:

// Example MCP tool invocation
{
  "tool": "trivy_generate_sbom",
  "arguments": {
    "target": "./",
    "format": "cyclonedx",
    "output": "./sbom.json"
  }
}

When GitHub Dependabot MCP Server is available:

// Example dependency update check
{
  "tool": "dependabot_check_updates",
  "arguments": {
    "repo": "owner/repo",
    "ecosystem": "npm"
  }
}

Package Manager Support

Node.js (npm/yarn/pnpm)

# Auto-detected files:
# - package.json
# - package-lock.json
# - yarn.lock
# - pnpm-lock.yaml

Java (Maven/Gradle)

# Auto-detected files:
# - pom.xml
# - build.gradle
# - build.gradle.kts

Python (pip/pipenv/poetry)

# Auto-detected files:
# - requirements.txt
# - Pipfile
# - pyproject.toml
# - setup.py

Ruby (Bundler)

# Auto-detected files:
# - Gemfile
# - Gemfile.lock

Go (Modules)

# Auto-detected files:
# - go.mod
# - go.sum

Rust (Cargo)

# Auto-detected files:
# - Cargo.toml
# - Cargo.lock

Best Practices

  1. Lock File Usage: Always include lock files for reproducible scans
  2. Regular Scanning: Integrate into CI/CD for continuous monitoring
  3. SBOM Storage: Store SBOMs alongside releases for compliance
  4. License Reviews: Review license changes in dependency updates
  5. Conflict Resolution: Address version conflicts before migration

Related Skills

  • vulnerability-scanner: Security scanning of dependencies
  • license-compliance-checker: Detailed license analysis
  • dependency-updater: Automated dependency updates

Related Agents

  • dependency-modernization-agent: Uses this skill for dependency management
  • migration-readiness-assessor: Uses this skill for readiness evaluation
  • security-vulnerability-assessor: Uses this skill for dependency security

References

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径library/specializations/code-migration-modernization/skills/dependency-scanner/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2115 个技能

同名技能的其他版本

有 2 个不同仓库或目录里都有叫 dependency-scanner 的技能。它们内容并不相同,别混用:

  • a5c-ai/babysitter — Software Composition Analysis (SCA) and dependency vulnerability scanning. Scan npm, pip,