Docs
Dependencies
Know which deps you'd lose sleep over before they get compromised. The build and pipeline dependencies that carry real risk - what each one does, its risk band, the compromise scenario, the patch path.
See it in motion
Where to find it
- Desktop:
localhost:4000, then Memory in the sidebar, then Reference index under All tools, in the Lessons, wiki and patterns group, which lists it. - Hosted:
repoops.ai/team/reference, from Memory in the sidebar, then Reference index under All tools, in the Lessons, wiki and patterns group, which lists it. - Keyboard: ⌘ K, then type “Dependencies”.
- On disk:
.claude/brain/dependencies.md
What it does for you
Risk-banded, not alphabetical.Deps are grouped by blast radius, and every row carries a risk band.
next and electron get a long row; the dev-only drizzle-kit gets a short one.Compromise scenario per dep.Each high-risk row names what happens if the package is compromised - credential exfil, build-time RCE, malware in the signed installer - and the patch path back to safety.
Patch path is written down, not improvised.When CVE-2026-xxxx drops at 11pm, the row already tells you which file to bump and which CI job will catch the regression.
Configure
Nothing - the doc is hand-curated. New runtime dep → new row here in the same PR (per the repo's “don't add a runtime dep without updating integrations + deps” rule).
Use it well
Before adding a runtime dependency, ask: is the existing dep set enough? If yes, don't add. If no, add the row here in the same PR with the risk band and compromise scenario. Quarterly: scan the list for deps you've outgrown.
Read more
Last updated