wu529778790/shenzjd-skills

dependency-audit

Use when auditing project dependencies for security vulnerabilities, outdated packages, or license compliance across npm/yarn/pnpm, pip, go, and cargo.

소스 보기
원본 Skill 문서

원본 저장소의 제목, 예시, 코드, 표, 링크, 이미지를 유지해 표시합니다.

Dependency Audit

扫描项目依赖,检测安全漏洞、过时包和 license 合规问题。

Overview

全面审计项目依赖:CVE 漏洞扫描、过时依赖检测、license 合规检查、重复依赖分析。输出按严重程度排序的安全报告和可执行的修复命令。

When to Use

  • User wants to check dependency security
  • User mentions CVE, vulnerability, or audit
  • User wants to know outdated dependencies
  • User says "审计依赖" / "check dependencies"
  • User inputs /dependency-audit

When NOT to Use:

  • User only wants to update versions
  • User wants code-level security review
  • User wants to analyze runtime dependencies
  • User wants deep license analysis
  • User wants to scan Docker images

Core Pattern

Step 1: 检测包管理器

检测文件包管理器审计命令
package-lock.jsonnpmnpm audit
yarn.lockyarnyarn audit
pnpm-lock.yamlpnpmpnpm audit
go.sumGogovulncheck ./...
requirements.txt / Pipfile.lockPythonpip-audit
Cargo.lockRustcargo audit

Step 2: 漏洞扫描

bash
# 工具可用性检查(所有步骤共用)
check_tool() {
  command -v "$1" >/dev/null 2>&1 || { echo "⚠️ $1 未安装,跳过 $2 审计"; return 1; }
}

核心命令(按包管理器分别执行,缺失工具自动跳过):

⚠️ npm audit 在发现漏洞时退出码非 0 —— 不要用 if npm audit ...; then 判断成功,直接解析 --json 输出:
包管理器审计命令
npm`npm audit --json \jq '.metadata.vulnerabilities.total'` → 解析 vulnerabilities 数量 + 严重程度(勿依赖退出码)
Gogovulncheck ./... → 安装 golang.org/x/vuln/cmd/govulncheck@latest
Pythonpip-audit → 安装: pip install pip-audit

输出:漏洞总数 + 按严重程度(critical/high/medium/low)分类的 CVE 列表。

Step 3: 过时依赖检测

核心命令(按包管理器分别执行,缺失工具自动跳过):

包管理器检测命令
npmnpx npm-check-updates --format table
Go`go list -m -u all \grep "\["`
Pythonpip list --outdated

统计:过时依赖数量、major/minor/patch 升级分布、是否有安全相关更新。

Step 4: License 合规检查

核心命令(按包管理器分别执行):

包管理器检测命令
npmnpx license-checker --json → 按许可证类型统计数量
Gogo-licenses csv ./... → 安装: go install github.com/google/go-licenses@latest

检测重点:GPL/AGPL 等 copyleft 许可证、未知/自定义许可证、许可证兼容性。

Step 5: 生成报告

使用 templates/audit-report.md 模板,输出:

  1. 安全概览 — 漏洞数量和严重程度分布
  2. 高危漏洞 — 需要立即修复的 CVE
  3. 过时依赖 — 按升级难度排序
  4. License 合规 — 风险许可证列表
  5. 修复命令 — 每个问题附带可执行命令

Quick Reference

bash
/dependency-audit                    # 完整审计
/dependency-audit --security         # 只检查安全漏洞
/dependency-audit --licenses         # 只检查 license
/dependency-audit --fix              # 自动修复可安全升级的依赖
参数说明默认值
--security只检查安全漏洞false
--licenses只检查 license 合规false
--fix自动修复false

Common Mistakes

错误正确做法原因
只看 high/criticalmedium 也需要关注很多攻击链从 medium 升级而来
盲目升级所有依赖逐个升级并测试major 升级可能有 breaking changes
不检查 transitive 依赖分析完整依赖树漏洞常出在间接依赖中
忽略 license 合规定期检查 licenseGPL 传染性风险
audit 后不更新 lock 文件重新生成 lock 文件确保修复生效
忽略已弃用的依赖检查弃用警告弃用包可能有安全风险
같은 저장소의 Skills

더 많은 Skills

모든 Skills
wu529778790
커뮤니티

db-migration-helper

Use when generating database migration SQL from model or schema changes — compares current vs desired schema, detects diffs, outputs reversible safe migrations.

설치 수
1
GitHub Stars
0
업데이트
8월 16일
wu529778790
커뮤니티

docker-build-deploy

Use when containerizing a Node.js app and setting up GitHub Actions CI/CD to build, push to GHCR, and deploy via SSH. Multi-stage build, non-root user, caching.

설치 수
1
GitHub Stars
0
업데이트
8월 16일
wu529778790
커뮤니티

git-hooks-setup

Use when setting up git hooks (pre-commit, commit-msg, pre-push) with husky or native hooks for linting, formatting, commit conventions, and secret scanning.

설치 수
1
GitHub Stars
0
업데이트
8월 16일
wu529778790
커뮤니티

github-figure-bed

Upload images to any GitHub repo as a figure bed and get CDN/markdown links (jsdelivr/jsdmirror/raw). One-time setup.sh guides gh login, auto-detects the owner, creates the default repo (img.shenzjd.com) if missing, and syncs config with the img.shenzjd.com web app via the repo's .imgx-config/config.json — upload with zero manual configuration. Use for uploading images to GitHub, generating CDN links, deleting/listing hosted images, or setting up a figure bed. Keywords: github figure bed, image host, CDN link, jsdelivr, jsdmirror, upload image to GitHub, 图床, 上传图片, CDN 链接, 初始化图床.

설치 수
1
GitHub Stars
0
업데이트
8월 16일