Communitygithub.com

mauricekleine/fluncle-maintenance

Keep Fluncle's pinned/baked supply chain current — the version-drift sweep over the Hermes image's pins (base image, bun, the fluncle CLI, the Claude Code CLI), the box.ascii render-box CLI, and the GitHub Actions tags. Ships the clearly-safe bumps END-TO-END (edit the pin → PR → CI green → merge); a baked Dockerfile pin then self-deploys via the on-box fluncle-pin-watch timer (rave-02): rebuild → pre-smoke → swap → auto-rollback. Brakes (reports, never ships) on anything risky — a major bump, the base image, or auth/runtime/model. ALSO owns the dependency VULNERABILITY posture: the two advisory feeds (Dependabot + the blocking bun-audit CI workflow), the severity policy, the justified `--ignore` allowlist, and vulnerability-driven bumps sequenced by reachability. Use whenever checking for version drift, bumping a pinned Hermes dependency, judging whether a base-image / CLI / Actions-tag bump is safe, SHA-pinning the workflow actions, merging a safe bump, triaging a security advisory or the bun-audit findings

fluncle-maintenance 是什麼?

fluncle-maintenance is a Claude Code agent skill that keep Fluncle's pinned/baked supply chain current — the version-drift sweep over the Hermes image's pins (base image, bun, the fluncle CLI, the Claude Code CLI), the box.ascii render-box CLI, and the GitHub Actions tags. Ships the clearly-safe bumps END-TO-END (edit the pin → PR → CI green → merge); a baked Dockerfile pin then self-deploys via the on-box fluncle-pin-watch timer (rave-02): rebuild → pre-smoke → swap → auto-rollback. Brakes (reports, never ships) on anything risky — a major bump, the base image, or auth/runtime/model. ALSO owns the dependency VULNERABILITY posture: the two advisory feeds (Dependabot + the blocking bun-audit CI workflow), the severity policy, the justified `--ignore` allowlist, and vulnerability-driven bumps sequenced by reachability. Use whenever checking for version drift, bumping a pinned Hermes dependency, judging whether a base-image / CLI / Actions-tag bump is safe, SHA-pinning the workflow actions, merging a safe bump, triaging a security advisory or the bun-audit findings.

相容平台Claude Code~Codex CLI~Cursor
npx skills add https://github.com/mauricekleine/fluncle/tree/main/.agents/skills/fluncle-maintenance

在你喜歡的 AI 中提問

開啟一個已預先載入此 Agent Skill 的新對話。

說明文件

fluncle-maintenance 是做什麼的?

Keep Fluncle's pinned/baked supply chain current — the version-drift sweep over the Hermes image's pins (base image, bun, the fluncle CLI, the Claude Code CLI), the box.ascii render-box CLI, and the GitHub Actions tags. Ships the clearly-safe bumps END-TO-END (edit the pin → PR → CI green → merge); a baked Dockerfile pin then self-deploys via the on-box fluncle-pin-watch timer (rave-02): rebuild → pre-smoke → swap → auto-rollback. Brakes (reports, never ships) on anything risky — a major bump, the base image, or auth/runtime/model. ALSO owns the dependency VULNERABILITY posture: the two advisory feeds (Dependabot + the blocking bun-audit CI workflow), the severity policy, the justified --ignore allowlist, and vulnerability-driven bumps sequenced by reachability. Use whenever checking for version drift, bumping a pinned Hermes dependency, judging whether a base-image / CLI / Actions-tag bump is safe, SHA-pinning the workflow actions, merging a safe bump, triaging a security advisory or the bun-audit findings

相關技能