Reviewing Dependency Changes

Guidance for tasks where a PR diff contains changes to dependency manifest files (package.json, .csproj, Cargo.toml, go.mod, requirements.txt, etc.) or when reviewing Renovate/Dependabot bot PRs. Evaluates new dependencies for AppSec…

About this skill

Guidance for tasks where a PR diff contains changes to dependency manifest files (package.json, .csproj, Cargo.toml, go.mod, requirements.txt, etc.) or when reviewing Renovate/Dependabot bot PRs. Evaluates new dependencies for AppSec approval process compliance, major version bump significance, lock file hygiene, and dependency removal completeness. Does NOT perform deep security or license analysis — that is handled by the bitwarden-security-engineer plugin's reviewing-dependencies skill.

Maintained by Bitwarden. The source includes the instructions and any supporting files needed to use this skill.

Inside the instructions

  • 01Manifest File Detection
  • 02Area 1: New Dependencies
  • 03What to Check
  • 04Approval Signals
  • 05Severity
  • 06What NOT to Flag

Before you start

  1. Read the instructions and check tool or account requirements.
  2. Install the complete folder when the skill references scripts or other files.
  3. Provide your task context, then review the agent's output.

Source

bitwarden/ai-plugins / reviewing-dependency-changes

Source reviewed October 2, 2026 · See publisher source