Docs

Dependencies

Know which deps you'd lose sleep over before they get compromised. The build and pipeline dependencies that carry real risk - what each one does, its risk band, the compromise scenario, the patch path.

See it in motion

Where to find it

  • Desktop: localhost:4000, then Memory in the sidebar, then Reference index under All tools, in the Lessons, wiki and patterns group, which lists it.
  • Hosted: repoops.ai/team/reference, from Memory in the sidebar, then Reference index under All tools, in the Lessons, wiki and patterns group, which lists it.
  • Keyboard: ⌘ K, then type “Dependencies”.
  • On disk: .claude/brain/dependencies.md

What it does for you

Risk-banded, not alphabetical.Deps are grouped by blast radius, and every row carries a risk band. next and electron get a long row; the dev-only drizzle-kit gets a short one.
Compromise scenario per dep.Each high-risk row names what happens if the package is compromised - credential exfil, build-time RCE, malware in the signed installer - and the patch path back to safety.
Patch path is written down, not improvised.When CVE-2026-xxxx drops at 11pm, the row already tells you which file to bump and which CI job will catch the regression.

Configure

Nothing - the doc is hand-curated. New runtime dep → new row here in the same PR (per the repo's “don't add a runtime dep without updating integrations + deps” rule).

Use it well

Before adding a runtime dependency, ask: is the existing dep set enough? If yes, don't add. If no, add the row here in the same PR with the risk band and compromise scenario. Quarterly: scan the list for deps you've outgrown.

Read more

Last updated