dependency-change-risk-review

$npx mdskill add Significant-Gravitas/skills-catalog/dependency-change-risk-review

Use this on a proposed plan, patch, or pull request.

SKILL.md

.github/skills/dependency-change-risk-reviewView on GitHub ↗
---
name: "dependency-change-risk-review"
description: "Review a dependency change for breaking APIs, runtime shifts, supply-chain risk, test gaps, rollout risk, and rollback quality."
triggers: ["review dependency change", "upgrade risk", "dependency PR review", "breaking change review", "package bump risk"]
version: "1"
---

# Dependency change risk review

Use this on a proposed plan, patch, or pull request.

## Review the evidence

Confirm the old and new resolved versions, source registry, checksums or lock
data, release and migration notes, maintainer status, and reason for change.
Flag renamed or transferred packages, install scripts, new binary downloads,
new permissions, and large transitive-tree changes.

## Review the application impact

Search for changed APIs, defaults, configuration, data formats, network calls,
and runtime requirements. Check production and development paths separately.
Map each risk to a test, manual check, rollout signal, or unresolved gap.

## Return a decision brief

Use **ready for review**, **needs changes**, or **blocked on evidence**. List
findings by impact, with file or source evidence, owner, and required action.
State whether rollback restores the old lock state and whether a data or config
change makes rollback unsafe.

Do not approve, merge, deploy, or waive a check. A clean diff does not prove a
safe runtime change.

More from Significant-Gravitas/skills-catalog

SkillDescription
account-health-and-qbrsUse when a support account wobbles or a quarterly business review looms: read the health signals, run the success plan, and prep the review from evidence.
accounts-receivable-follow-upReview open receivables and draft factual, staged payment follow-ups without inventing status or contacting a customer.
ad-copy-variantsWrite ad variants that each test one idea, within platform limits and supported claims.
alex-getting-startedUse on the first conversation with Alex, or whenever their memory has no product preferences yet: learn what the user is building and who for, where specs, roadmap and numbers live, who decides dates and scope, and get them to a first real product deliverable.
alliance-co-commercializationUse when a strategic alliance needs joint selling governance: operating model, joint targeting, steering prep, and milestone accountability.
anika-getting-startedUse on the first conversation with Anika, or whenever their memory has no partnership preferences yet: learn which partners and alliances the user owns, what motion they run, and get one real partner read on screen in the same session.
assure-partner-led-deliveryUse when partners deliver client work in your name: own the in-flight book, run the weekly delivery review, and rescue engagements before clients feel it.
automate-finance-reportingUse to connect a number source, map an export into the finance ledger, or QA a sheet: the column mapping, the dedupe key, the load summary, and the checks that must pass before a read ships.
billing-refunds-and-exceptionsUse when money is on the table: verify the charge, check the policy, and stage a refund or exception draft that stops at the owner's yes.
board-and-investor-metrics-briefPrepare a concise board or investor metrics brief with definitions, sources, comparisons, drivers, risks, and decisions needed.