SkillVaultskills Browse all 500 skills

Maintenance · Version 1.6.0 · Reviewed 2026-08-02

Dependency Vendoring Advisor

Reduce change risk for fork decision and maintenance burden with evidence, explicit trade-offs, and a verification plan.

4 method steps 4 documented failure modes 4 diagnostic checks 7 quality gates

Decides when to vendor, fork, or replace a dependency and how to carry that decision forward.

₹149 one-time

Get this skill archive

What this skill helps you do

  • Fork decision
  • Maintenance burden
  • Upstream strategy

How Dependency Vendoring Advisor works

You provide

Current versions, changelogs, support dates, and coverage

It inspects

Breaking changes and transitive pins behind fork decision

It decides

A maintenance burden sequence taking one major at a time

You verify

Suite green between increments with rollback proven

What it checks first

Dependency Vendoring Advisor decides when to vendor, fork, or replace a dependency and how to carry that decision forward. Use it when the work involves Fork decision, Maintenance burden, Upstream strategy.

  1. Whether the current version is still supported, and the date support actually ends.
  2. How many major versions separate current from target, since each carries its own breaking changes.
  3. Whether test coverage is sufficient to detect a behavioral regression from the upgrade.
  4. Transitive dependencies that constrain the upgrade regardless of direct requirements.

Failure modes it recognizes

  • Skipping intermediate majors so several sets of breaking changes land together, unattributable.
  • A deprecation warning ignored until the removal makes the upgrade a project.
  • A transitive dependency pinning an old version, silently blocking the direct upgrade.
  • An upgrade completed without a rollback path because a data format changed.

Answers it will reject

  • Upgrading everything at once to reduce disruption, which maximizes debugging cost.
  • Treating a green build as sufficient evidence when coverage of the changed behavior is thin.
  • Deferring an end-of-life migration until support has already lapsed.

Decision rules it applies

  • Upgrade one major at a time with the suite green between each step.
  • Resolve deprecation warnings from version N before starting N+1; they are the removal list.
  • Plan end-of-life migrations against the support date, not against convenience.

Evidence it asks for

  • Inventory direct and transitive versions against their support timelines.
  • Run the suite between each increment and record which behavior changed.
  • Verify rollback by deploying the previous version against the upgraded data.

The method inside

  1. Map the artifact, actors, boundaries, and invariants relevant to fork decision.
  2. Trace concrete failure or abuse paths for maintenance burden; do not report checklist items without a mechanism.
  3. Prioritize upstream strategy findings by impact, likelihood, confidence, and cost of correction.
  4. Recommend the smallest defensible change, then define how an independent reviewer can verify it.

Deliverables

  • Fork decision assessment
  • Maintenance burden decision and action plan
  • Upstream strategy verification checklist

Evidence requirements

  • Current and target versions
  • Dependency graph and changelogs
  • Tests, compatibility constraints, and rollout environment

Quality gates

  • Every material claim traces to supplied evidence or is labeled as a hypothesis.
  • The response follows the declared deliverable contract.
  • No execution, access, measurement, or verification is invented.
  • Secrets and personal data are redacted rather than repeated.
  • The user receives a concrete independent verification step.
  • The relevant failure modes in this domain were considered rather than only the reported symptom.
  • No listed anti-pattern was recommended as a solution.

Example task

Input

A dependency we rely on has been unmaintained for two years and has an open security issue.

Expected output

Unmaintained plus a security issue means the decision is now, not later. Assess how much of the library you actually use: often a small vendored subset removes the risk entirely, whereas forking commits you to tracking a codebase you did not write...

Boundaries and compatibility

Ideal for

  • Fork decision: produce a decision or artifact grounded in supplied evidence.
  • Maintenance burden: produce a decision or artifact grounded in supplied evidence.
  • Upstream strategy: produce a decision or artifact grounded in supplied evidence.

Out of scope

  • Blindly upgrading across multiple major versions
  • Assuming semantic versioning guarantees compatibility

Agent compatibility

  • GitHub Copilot custom agents
  • Claude Agent Skills / SKILL.md
  • Any instruction-following chat model

Tool policy: Advisory by default. No tools are assumed. If the host provides tools, use read-only evidence gathering unless the user explicitly approves a scoped write or execution action.