Copy over dependency update skill from random-bunny repo #38

Open
opened 2026-09-10 18:17:17 +01:00 by Vylpes · 3 comments
Owner

Epic:
Story Points: 5


Copy the release dependency-audit Cursor skill from RabbitLabs/random-bunny (.cursor/skills/dependency-audit/ on feature/268-2-5-0-dependencies) into this repo, adapted for Rust/Cargo.

Description

random-bunny's skill guides agents through a release dependency audit: fix vulnerabilities, apply within-range updates, document results, and file Forgejo tickets for deferred major bumps. Calculator already has .cursor/skills/generate-criteria and generate-test-plan; this adds the matching dependency-audit workflow using cargo audit, cargo update, cargo test, and cargo build.

Source files to port/adapt:

  • SKILL.md — main workflow (9 steps)
  • major-bump-issue.md — Forgejo issue body template for deferred majors
  • overview-template.md — docs/dependency-audit-{version}.md structure

Acceptance Criteria

GIVEN the random-bunny dependency-audit skill as the reference
WHEN this story is complete
THEN .cursor/skills/dependency-audit/SKILL.md exists with the full release audit checklist adapted for calculator

GIVEN calculator uses Cargo (Cargo.toml, Cargo.lock)
WHEN the skill lists audit / update / verify commands
THEN it uses cargo audit, cargo update, cargo test, and cargo build (not yarn/npm)

GIVEN supporting templates are part of the skill
WHEN this story is complete
THEN major-bump-issue.md and overview-template.md are present and reference calculator paths (.forgejo/ISSUE_TEMPLATE, docs/dependency-audit-{version}.md)

GIVEN a deferred major crate upgrade is found during an audit
WHEN the skill instructs ticket creation
THEN it specifies Forgejo MCP with type/dependencies + needs/estimate labels and links to the overview doc

GIVEN an audit produces documentation
WHEN the skill describes output
THEN the overview is written to docs/dependency-audit-{version}.md per the template (metrics, vuln fixes, within-range bumps, deferred majors, verification, files changed)

GIVEN release planning ties audits to tracking issues
WHEN an audit completes
THEN the skill instructs posting the full overview markdown as a comment on the open {version} Dependency Updates issue

GIVEN the source skill is Node-oriented
WHEN adapted for Rust
THEN yarn/npm/lockfile/script references are replaced with Cargo equivalents; note cargo-audit must be installed where relevant

Subtasks

  • Copy SKILL.md and adapt for Cargo workflow
  • Copy and adapt major-bump-issue.md (calculator issue template paths)
  • Copy and adapt overview-template.md (Cargo.toml / Cargo.lock instead of package.json / lockfile)
  • Verify skill sits under .cursor/skills/dependency-audit/ next to existing skills

Notes

Epic: Story Points: 5 --- Copy the release **dependency-audit** Cursor skill from `RabbitLabs/random-bunny` (`.cursor/skills/dependency-audit/` on `feature/268-2-5-0-dependencies`) into this repo, adapted for Rust/Cargo. ## Description random-bunny's skill guides agents through a release dependency audit: fix vulnerabilities, apply within-range updates, document results, and file Forgejo tickets for deferred major bumps. Calculator already has `.cursor/skills/generate-criteria` and `generate-test-plan`; this adds the matching dependency-audit workflow using `cargo audit`, `cargo update`, `cargo test`, and `cargo build`. **Source files to port/adapt:** - `SKILL.md` — main workflow (9 steps) - `major-bump-issue.md` — Forgejo issue body template for deferred majors - `overview-template.md` — `docs/dependency-audit-{version}.md` structure ## Acceptance Criteria GIVEN the random-bunny `dependency-audit` skill as the reference WHEN this story is complete THEN `.cursor/skills/dependency-audit/SKILL.md` exists with the full release audit checklist adapted for calculator GIVEN calculator uses Cargo (`Cargo.toml`, `Cargo.lock`) WHEN the skill lists audit / update / verify commands THEN it uses `cargo audit`, `cargo update`, `cargo test`, and `cargo build` (not yarn/npm) GIVEN supporting templates are part of the skill WHEN this story is complete THEN `major-bump-issue.md` and `overview-template.md` are present and reference calculator paths (`.forgejo/ISSUE_TEMPLATE`, `docs/dependency-audit-{version}.md`) GIVEN a deferred major crate upgrade is found during an audit WHEN the skill instructs ticket creation THEN it specifies Forgejo MCP with `type/dependencies` + `needs/estimate` labels and links to the overview doc GIVEN an audit produces documentation WHEN the skill describes output THEN the overview is written to `docs/dependency-audit-{version}.md` per the template (metrics, vuln fixes, within-range bumps, deferred majors, verification, files changed) GIVEN release planning ties audits to tracking issues WHEN an audit completes THEN the skill instructs posting the full overview markdown as a comment on the open `{version} Dependency Updates` issue GIVEN the source skill is Node-oriented WHEN adapted for Rust THEN yarn/npm/lockfile/script references are replaced with Cargo equivalents; note `cargo-audit` must be installed where relevant ## Subtasks - [ ] Copy `SKILL.md` and adapt for Cargo workflow - [ ] Copy and adapt `major-bump-issue.md` (calculator issue template paths) - [ ] Copy and adapt `overview-template.md` (`Cargo.toml` / `Cargo.lock` instead of `package.json` / lockfile) - [ ] Verify skill sits under `.cursor/skills/dependency-audit/` next to existing skills ## Notes - Source: https://git.vylpes.xyz/RabbitLabs/random-bunny/src/branch/feature/268-2-5-0-dependencies/.cursor/skills/dependency-audit/ - Out of scope: running an audit, changing lockfiles, or creating deferred-major issues (those happen when the skill is used on a release)
Vylpes added this to the 0.1.0 milestone 2026-09-10 18:17:17 +01:00
Member

Acceptance criteria (needs/criteria)

Source skill: RabbitLabs/random-bunny → .cursor/skills/dependency-audit/ (on feature/268-2-5-0-dependencies; three files: SKILL.md, major-bump-issue.md, overview-template.md).

Calculator is a Rust/Cargo project (Cargo.toml / Cargo.lock). The copied skill must follow the same release-audit workflow as random-bunny but use Cargo tooling instead of Yarn/npm.

Scope

  • Add .cursor/skills/dependency-audit/ alongside existing generate-criteria and generate-test-plan skills.
  • Adapt workflow steps (baseline → audit → fix vulns → within-range updates → verify → overview doc → deferred-major Forgejo tickets → comment on release dependency issue).
  • Do not run an audit or change lockfiles in this story — deliver the skill files only.

Acceptance criteria

GIVEN the random-bunny dependency-audit skill as the reference implementation
WHEN this story is complete
THEN .cursor/skills/dependency-audit/SKILL.md exists and documents a 9-step release dependency audit checklist for calculator

GIVEN calculator uses Cargo
WHEN the skill describes audit / update / verify commands
THEN it uses cargo audit (vulnerability scan), cargo update (within existing semver ranges in Cargo.toml), cargo test, and cargo build — not yarn/npm

GIVEN the skill includes supporting templates
WHEN this story is complete
THEN major-bump-issue.md and overview-template.md are present and reference calculator conventions (.forgejo/ISSUE_TEMPLATE, docs/dependency-audit-{version}.md, Cargo.toml / Cargo.lock)

GIVEN a deferred major crate upgrade is identified during an audit
WHEN the skill instructs ticket creation
THEN it specifies Forgejo MCP (user-forgejo) with type/dependencies + needs/estimate labels and links to the overview doc — matching RabbitLabs patterns from random-bunny #268-style issues

GIVEN the skill describes documentation output
WHEN an audit completes
THEN the overview is written to docs/dependency-audit-{version}.md using the overview template structure (before/after metrics, vuln fixes, within-range bumps, deferred majors table, verification commands, files changed)

GIVEN the skill describes interaction with release planning
WHEN an audit finishes
THEN it instructs posting the full overview markdown as a comment on the open release dependency issue (title like {version} Dependency Updates)

GIVEN the skill is copied from a Node project
WHEN adapted for calculator
THEN yarn/npm-specific examples, lockfile names, and script references (yarn test, package.json resolutions/overrides) are replaced with Cargo equivalents or removed; Rust-specific notes (e.g. cargo audit requires cargo-audit installed) are included where relevant

Out of scope

  • Performing a dependency audit on a release branch
  • Bumping Cargo.toml versions or committing Cargo.lock changes
  • Creating Forgejo issues for deferred majors

Advancing needs/criteria → needs/estimate. Issue body updated with these criteria.

## Acceptance criteria (needs/criteria) Source skill: `RabbitLabs/random-bunny` → `.cursor/skills/dependency-audit/` (on `feature/268-2-5-0-dependencies`; three files: `SKILL.md`, `major-bump-issue.md`, `overview-template.md`). Calculator is a **Rust/Cargo** project (`Cargo.toml` / `Cargo.lock`). The copied skill must follow the same release-audit workflow as random-bunny but use Cargo tooling instead of Yarn/npm. ### Scope - Add `.cursor/skills/dependency-audit/` alongside existing `generate-criteria` and `generate-test-plan` skills. - Adapt workflow steps (baseline → audit → fix vulns → within-range updates → verify → overview doc → deferred-major Forgejo tickets → comment on release dependency issue). - Do **not** run an audit or change lockfiles in this story — deliver the skill files only. ### Acceptance criteria GIVEN the random-bunny `dependency-audit` skill as the reference implementation WHEN this story is complete THEN `.cursor/skills/dependency-audit/SKILL.md` exists and documents a 9-step release dependency audit checklist for **calculator** GIVEN calculator uses Cargo WHEN the skill describes audit / update / verify commands THEN it uses `cargo audit` (vulnerability scan), `cargo update` (within existing semver ranges in `Cargo.toml`), `cargo test`, and `cargo build` — not yarn/npm GIVEN the skill includes supporting templates WHEN this story is complete THEN `major-bump-issue.md` and `overview-template.md` are present and reference calculator conventions (`.forgejo/ISSUE_TEMPLATE`, `docs/dependency-audit-{version}.md`, `Cargo.toml` / `Cargo.lock`) GIVEN a deferred major crate upgrade is identified during an audit WHEN the skill instructs ticket creation THEN it specifies Forgejo MCP (`user-forgejo`) with `type/dependencies` + `needs/estimate` labels and links to the overview doc — matching RabbitLabs patterns from random-bunny #268-style issues GIVEN the skill describes documentation output WHEN an audit completes THEN the overview is written to `docs/dependency-audit-{version}.md` using the overview template structure (before/after metrics, vuln fixes, within-range bumps, deferred majors table, verification commands, files changed) GIVEN the skill describes interaction with release planning WHEN an audit finishes THEN it instructs posting the full overview markdown as a comment on the open release dependency issue (title like `{version} Dependency Updates`) GIVEN the skill is copied from a Node project WHEN adapted for calculator THEN yarn/npm-specific examples, lockfile names, and script references (`yarn test`, `package.json` resolutions/overrides) are replaced with Cargo equivalents or removed; Rust-specific notes (e.g. `cargo audit` requires `cargo-audit` installed) are included where relevant ### Out of scope - Performing a dependency audit on a release branch - Bumping `Cargo.toml` versions or committing `Cargo.lock` changes - Creating Forgejo issues for deferred majors --- Advancing **needs/criteria → needs/estimate**. Issue body updated with these criteria.
Member

Story point estimate (needs/estimate)

Estimate: 5

Criteria are specific (three skill files, Cargo command mapping, Forgejo ticket pattern, overview doc path, out-of-scope boundaries). Work is documentation/skill port only — no runtime code or lockfile changes.

Slice Points Notes
Adapt SKILL.md (9-step audit checklist, Cargo commands, release-issue comment step) 3 Largest file; replace yarn/npm with cargo audit / cargo update / cargo test / cargo build
Adapt major-bump-issue.md + overview-template.md 1 Calculator paths (.forgejo/ISSUE_TEMPLATE, docs/dependency-audit-{version}.md, Cargo.toml / Cargo.lock)
Add .cursor/skills/dependency-audit/ and verify alongside existing skills 1 Layout + spot-check references

Comparable to other calculator 5-point stories (#30 stdin pipe, #31 session save) in planning depth; lower implementation risk because deliverable is markdown only.


Advancing needs/estimate → needs/tests. Story Points set to 5 on the issue body.

## Story point estimate (needs/estimate) **Estimate: 5** Criteria are specific (three skill files, Cargo command mapping, Forgejo ticket pattern, overview doc path, out-of-scope boundaries). Work is documentation/skill port only — no runtime code or lockfile changes. | Slice | Points | Notes | |-------|--------|-------| | Adapt `SKILL.md` (9-step audit checklist, Cargo commands, release-issue comment step) | 3 | Largest file; replace yarn/npm with `cargo audit` / `cargo update` / `cargo test` / `cargo build` | | Adapt `major-bump-issue.md` + `overview-template.md` | 1 | Calculator paths (`.forgejo/ISSUE_TEMPLATE`, `docs/dependency-audit-{version}.md`, `Cargo.toml` / `Cargo.lock`) | | Add `.cursor/skills/dependency-audit/` and verify alongside existing skills | 1 | Layout + spot-check references | Comparable to other calculator **5**-point stories (#30 stdin pipe, #31 session save) in planning depth; lower implementation risk because deliverable is markdown only. --- Advancing **needs/estimate → needs/tests**. Story Points set to **5** on the issue body.
Member

QA test plan (needs/tests)

Manual verification on a branch that implements this story (no code in this planning step). Each script maps to acceptance criteria in the issue body.

Setup

  • Check out the implementation branch locally.
  • Confirm repo root is the calculator Rust project (Cargo.toml present).

TC-1 — Skill directory layout

Covers: GIVEN the random-bunny skill … THEN .cursor/skills/dependency-audit/SKILL.md exists

  1. List .cursor/skills/.
  2. Expected: dependency-audit/ exists alongside generate-criteria and generate-test-plan.
  3. Expected: dependency-audit/SKILL.md is non-empty and describes a multi-step release dependency audit for calculator.

TC-2 — Cargo commands (no yarn/npm)

Covers: GIVEN calculator uses Cargo … THEN cargo audit, cargo update, cargo test, cargo build

  1. Open SKILL.md and search for yarn, npm, and package.json.
  2. Expected: No yarn/npm workflow instructions remain (except optional “replaced from source” notes if any).
  3. Expected: Audit/update/verify steps reference cargo audit, cargo update, cargo test, and cargo build.
  4. Expected: Any vulnerability-scan step mentions cargo-audit installation where relevant.

TC-3 — Supporting templates present

Covers: GIVEN supporting templates … THEN major-bump-issue.md and overview-template.md

  1. Confirm files exist under .cursor/skills/dependency-audit/:
    • major-bump-issue.md
    • overview-template.md
  2. Expected: Templates reference calculator paths (.forgejo/ISSUE_TEMPLATE, docs/dependency-audit-{version}.md, Cargo.toml / Cargo.lock).

TC-4 — Deferred major ticket instructions

Covers: GIVEN deferred major … THEN Forgejo MCP with type/dependencies + needs/estimate

  1. Read SKILL.md and/or major-bump-issue.md sections on deferred majors.
  2. Expected: Instructions to file Forgejo issues with labels type/dependencies and needs/estimate.
  3. Expected: Overview doc path docs/dependency-audit-{version}.md is linked or referenced in the ticket template.

TC-5 — Overview documentation output

Covers: GIVEN audit produces documentation … THEN docs/dependency-audit-{version}.md

  1. Open overview-template.md.
  2. Expected: Sections for metrics, vulnerability fixes, within-range bumps, deferred majors, verification commands, and files changed.
  3. Expected: Placeholders use {version} and Cargo lockfile naming (Cargo.lock).

TC-6 — Release dependency issue comment

Covers: GIVEN release planning … THEN post overview as comment on {version} Dependency Updates issue

  1. In SKILL.md, locate the final reporting step.
  2. Expected: Instructs posting the full overview markdown as a comment on the open release dependency tracking issue (title pattern {version} Dependency Updates).

TC-7 — Out of scope respected (spot check)

Covers: story notes / out of scope

  1. Expected: Skill does not require committing lockfile changes or running a live audit as part of this story’s deliverable check — only that the skill describes those steps for future release use.

Pass criteria

All TC-1–TC-7 Expected results hold on the implementation branch.


Advancing needs/tests → needs/approval. Assigning Vylpes for approval (Smithy-bot planning complete).

## QA test plan (needs/tests) Manual verification on a branch that implements this story (no code in this planning step). Each script maps to acceptance criteria in the issue body. ### Setup - Check out the implementation branch locally. - Confirm repo root is the calculator Rust project (`Cargo.toml` present). --- ### TC-1 — Skill directory layout **Covers:** *GIVEN the random-bunny skill … THEN `.cursor/skills/dependency-audit/SKILL.md` exists* 1. List `.cursor/skills/`. 2. **Expected:** `dependency-audit/` exists alongside `generate-criteria` and `generate-test-plan`. 3. **Expected:** `dependency-audit/SKILL.md` is non-empty and describes a multi-step release dependency audit for **calculator**. --- ### TC-2 — Cargo commands (no yarn/npm) **Covers:** *GIVEN calculator uses Cargo … THEN `cargo audit`, `cargo update`, `cargo test`, `cargo build`* 1. Open `SKILL.md` and search for `yarn`, `npm`, and `package.json`. 2. **Expected:** No yarn/npm workflow instructions remain (except optional “replaced from source” notes if any). 3. **Expected:** Audit/update/verify steps reference `cargo audit`, `cargo update`, `cargo test`, and `cargo build`. 4. **Expected:** Any vulnerability-scan step mentions `cargo-audit` installation where relevant. --- ### TC-3 — Supporting templates present **Covers:** *GIVEN supporting templates … THEN `major-bump-issue.md` and `overview-template.md`* 1. Confirm files exist under `.cursor/skills/dependency-audit/`: - `major-bump-issue.md` - `overview-template.md` 2. **Expected:** Templates reference calculator paths (`.forgejo/ISSUE_TEMPLATE`, `docs/dependency-audit-{version}.md`, `Cargo.toml` / `Cargo.lock`). --- ### TC-4 — Deferred major ticket instructions **Covers:** *GIVEN deferred major … THEN Forgejo MCP with `type/dependencies` + `needs/estimate`* 1. Read `SKILL.md` and/or `major-bump-issue.md` sections on deferred majors. 2. **Expected:** Instructions to file Forgejo issues with labels `type/dependencies` and `needs/estimate`. 3. **Expected:** Overview doc path `docs/dependency-audit-{version}.md` is linked or referenced in the ticket template. --- ### TC-5 — Overview documentation output **Covers:** *GIVEN audit produces documentation … THEN `docs/dependency-audit-{version}.md`* 1. Open `overview-template.md`. 2. **Expected:** Sections for metrics, vulnerability fixes, within-range bumps, deferred majors, verification commands, and files changed. 3. **Expected:** Placeholders use `{version}` and Cargo lockfile naming (`Cargo.lock`). --- ### TC-6 — Release dependency issue comment **Covers:** *GIVEN release planning … THEN post overview as comment on `{version} Dependency Updates` issue* 1. In `SKILL.md`, locate the final reporting step. 2. **Expected:** Instructs posting the full overview markdown as a comment on the open release dependency tracking issue (title pattern `{version} Dependency Updates`). --- ### TC-7 — Out of scope respected (spot check) **Covers:** story notes / out of scope 1. **Expected:** Skill does not require committing lockfile changes or running a live audit as part of *this* story’s deliverable check — only that the skill *describes* those steps for future release use. --- ### Pass criteria All TC-1–TC-7 **Expected** results hold on the implementation branch. --- Advancing **needs/tests → needs/approval**. Assigning **Vylpes** for approval (Smithy-bot planning complete).
Smithy-bot removed their assignment 2026-09-28 12:21:39 +01:00
Vylpes removed their assignment 2026-09-28 16:42:54 +01:00
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
RabbitLabs/calculator#38
No description provided.