dependency-hygiene
Installation
SKILL.md
Dependency hygiene
Every dependency is a permanent liability someone else may have to service. Optimise for resolves and builds years from now, not for latest. This skill governs pubspec/lock mechanics, the gate a new package must pass, and the escape hatch when a critical package rots.
Read the reference for the task at hand:
references/dependency-gate-and-audit.md— the refuse/accept gate, transitive auditing, licence recording, upgrade discipline.references/sdk-pin-and-lint-include.md— recording the SDK version and the silent-lint-disable trap on any SDK bump.references/vendoring-behind-an-interface.md— vendoring a bus-factor-1 native plugin intothird_party/without touchinglib/.
Run scripts/audit-deps.sh before a PR that changes pubspec.yaml.