Copy over dependency update skill from random-bunny repo #38
Labels
No labels
blocked
duplicate
needs
approval
needs
criteria
needs
estimate
needs
tests
question
step
doing
step
review
step
testing
step
todo
step
uat
type
admin
type
alert
type
bug
type
change
type
defect
type
dependencies
type
epic
type
idea
type
incident
type
investigation
type
spike
type
story
won't fix
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
RabbitLabs/calculator#38
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Epic:
Story Points: 5
Copy the release dependency-audit Cursor skill from
RabbitLabs/random-bunny(.cursor/skills/dependency-audit/onfeature/268-2-5-0-dependencies) into this repo, adapted for Rust/Cargo.Description
random-bunny's skill guides agents through a release dependency audit: fix vulnerabilities, apply within-range updates, document results, and file Forgejo tickets for deferred major bumps. Calculator already has
.cursor/skills/generate-criteriaandgenerate-test-plan; this adds the matching dependency-audit workflow usingcargo audit,cargo update,cargo test, andcargo build.Source files to port/adapt:
SKILL.md— main workflow (9 steps)major-bump-issue.md— Forgejo issue body template for deferred majorsoverview-template.md—docs/dependency-audit-{version}.mdstructureAcceptance Criteria
GIVEN the random-bunny
dependency-auditskill as the referenceWHEN this story is complete
THEN
.cursor/skills/dependency-audit/SKILL.mdexists with the full release audit checklist adapted for calculatorGIVEN calculator uses Cargo (
Cargo.toml,Cargo.lock)WHEN the skill lists audit / update / verify commands
THEN it uses
cargo audit,cargo update,cargo test, andcargo build(not yarn/npm)GIVEN supporting templates are part of the skill
WHEN this story is complete
THEN
major-bump-issue.mdandoverview-template.mdare present and reference calculator paths (.forgejo/ISSUE_TEMPLATE,docs/dependency-audit-{version}.md)GIVEN a deferred major crate upgrade is found during an audit
WHEN the skill instructs ticket creation
THEN it specifies Forgejo MCP with
type/dependencies+needs/estimatelabels and links to the overview docGIVEN an audit produces documentation
WHEN the skill describes output
THEN the overview is written to
docs/dependency-audit-{version}.mdper the template (metrics, vuln fixes, within-range bumps, deferred majors, verification, files changed)GIVEN release planning ties audits to tracking issues
WHEN an audit completes
THEN the skill instructs posting the full overview markdown as a comment on the open
{version} Dependency UpdatesissueGIVEN the source skill is Node-oriented
WHEN adapted for Rust
THEN yarn/npm/lockfile/script references are replaced with Cargo equivalents; note
cargo-auditmust be installed where relevantSubtasks
SKILL.mdand adapt for Cargo workflowmajor-bump-issue.md(calculator issue template paths)overview-template.md(Cargo.toml/Cargo.lockinstead ofpackage.json/ lockfile).cursor/skills/dependency-audit/next to existing skillsNotes
Acceptance criteria (needs/criteria)
Source skill:
RabbitLabs/random-bunny→.cursor/skills/dependency-audit/(onfeature/268-2-5-0-dependencies; three files:SKILL.md,major-bump-issue.md,overview-template.md).Calculator is a Rust/Cargo project (
Cargo.toml/Cargo.lock). The copied skill must follow the same release-audit workflow as random-bunny but use Cargo tooling instead of Yarn/npm.Scope
.cursor/skills/dependency-audit/alongside existinggenerate-criteriaandgenerate-test-planskills.Acceptance criteria
GIVEN the random-bunny
dependency-auditskill as the reference implementationWHEN this story is complete
THEN
.cursor/skills/dependency-audit/SKILL.mdexists and documents a 9-step release dependency audit checklist for calculatorGIVEN calculator uses Cargo
WHEN the skill describes audit / update / verify commands
THEN it uses
cargo audit(vulnerability scan),cargo update(within existing semver ranges inCargo.toml),cargo test, andcargo build— not yarn/npmGIVEN the skill includes supporting templates
WHEN this story is complete
THEN
major-bump-issue.mdandoverview-template.mdare present and reference calculator conventions (.forgejo/ISSUE_TEMPLATE,docs/dependency-audit-{version}.md,Cargo.toml/Cargo.lock)GIVEN a deferred major crate upgrade is identified during an audit
WHEN the skill instructs ticket creation
THEN it specifies Forgejo MCP (
user-forgejo) withtype/dependencies+needs/estimatelabels and links to the overview doc — matching RabbitLabs patterns from random-bunny #268-style issuesGIVEN the skill describes documentation output
WHEN an audit completes
THEN the overview is written to
docs/dependency-audit-{version}.mdusing the overview template structure (before/after metrics, vuln fixes, within-range bumps, deferred majors table, verification commands, files changed)GIVEN the skill describes interaction with release planning
WHEN an audit finishes
THEN it instructs posting the full overview markdown as a comment on the open release dependency issue (title like
{version} Dependency Updates)GIVEN the skill is copied from a Node project
WHEN adapted for calculator
THEN yarn/npm-specific examples, lockfile names, and script references (
yarn test,package.jsonresolutions/overrides) are replaced with Cargo equivalents or removed; Rust-specific notes (e.g.cargo auditrequirescargo-auditinstalled) are included where relevantOut of scope
Cargo.tomlversions or committingCargo.lockchangesAdvancing needs/criteria → needs/estimate. Issue body updated with these criteria.
Story point estimate (needs/estimate)
Estimate: 5
Criteria are specific (three skill files, Cargo command mapping, Forgejo ticket pattern, overview doc path, out-of-scope boundaries). Work is documentation/skill port only — no runtime code or lockfile changes.
SKILL.md(9-step audit checklist, Cargo commands, release-issue comment step)cargo audit/cargo update/cargo test/cargo buildmajor-bump-issue.md+overview-template.md.forgejo/ISSUE_TEMPLATE,docs/dependency-audit-{version}.md,Cargo.toml/Cargo.lock).cursor/skills/dependency-audit/and verify alongside existing skillsComparable to other calculator 5-point stories (#30 stdin pipe, #31 session save) in planning depth; lower implementation risk because deliverable is markdown only.
Advancing needs/estimate → needs/tests. Story Points set to 5 on the issue body.
QA test plan (needs/tests)
Manual verification on a branch that implements this story (no code in this planning step). Each script maps to acceptance criteria in the issue body.
Setup
Cargo.tomlpresent).TC-1 — Skill directory layout
Covers: GIVEN the random-bunny skill … THEN
.cursor/skills/dependency-audit/SKILL.mdexists.cursor/skills/.dependency-audit/exists alongsidegenerate-criteriaandgenerate-test-plan.dependency-audit/SKILL.mdis non-empty and describes a multi-step release dependency audit for calculator.TC-2 — Cargo commands (no yarn/npm)
Covers: GIVEN calculator uses Cargo … THEN
cargo audit,cargo update,cargo test,cargo buildSKILL.mdand search foryarn,npm, andpackage.json.cargo audit,cargo update,cargo test, andcargo build.cargo-auditinstallation where relevant.TC-3 — Supporting templates present
Covers: GIVEN supporting templates … THEN
major-bump-issue.mdandoverview-template.md.cursor/skills/dependency-audit/:major-bump-issue.mdoverview-template.md.forgejo/ISSUE_TEMPLATE,docs/dependency-audit-{version}.md,Cargo.toml/Cargo.lock).TC-4 — Deferred major ticket instructions
Covers: GIVEN deferred major … THEN Forgejo MCP with
type/dependencies+needs/estimateSKILL.mdand/ormajor-bump-issue.mdsections on deferred majors.type/dependenciesandneeds/estimate.docs/dependency-audit-{version}.mdis linked or referenced in the ticket template.TC-5 — Overview documentation output
Covers: GIVEN audit produces documentation … THEN
docs/dependency-audit-{version}.mdoverview-template.md.{version}and Cargo lockfile naming (Cargo.lock).TC-6 — Release dependency issue comment
Covers: GIVEN release planning … THEN post overview as comment on
{version} Dependency UpdatesissueSKILL.md, locate the final reporting step.{version} Dependency Updates).TC-7 — Out of scope respected (spot check)
Covers: story notes / out of scope
Pass criteria
All TC-1–TC-7 Expected results hold on the implementation branch.
Advancing needs/tests → needs/approval. Assigning Vylpes for approval (Smithy-bot planning complete).