Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
backnotprop avatar

Review Renovate

  • 88 installs
  • 7.5k repo stars
  • Updated August 5, 2026
  • backnotprop/plannotator

review-renovate is a Claude skill that reviews Renovate GitHub Actions PRs, verifying pinned SHAs against upstream tags for supply-chain integrity.

About

review-renovate reviews Renovate bot pull requests that update GitHub Actions dependencies. It verifies each pinned commit SHA against the upstream tagged release to confirm supply-chain integrity, reviews changelogs for breaking changes, and checks workflow compatibility before giving a merge recommendation. A developer uses it when a Renovate PR changes actions in .github/workflows/.

  • Reviews Renovate bot PRs that update GitHub Actions dependencies
  • Verifies pinned commit SHAs against upstream tagged releases for supply-chain integrity
  • Checks changelogs for breaking changes and gives a safe-to-merge verdict

Review Renovate by the numbers

  • 88 all-time installs (skills.sh)
  • Ranked #1,051 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

review-renovate capabilities & compatibility

Capabilities
code review · security audit
Works with
github
Use cases
security audit · ci cd · code review
From the docs

What review-renovate says it does

Verifies supply chain integrity by checking pinned commit SHAs against upstream tagged releases
SKILL.md
If any SHA does not match, **stop and report a supply chain integrity failure**. Do not approve the PR.
SKILL.md
npx skills add https://github.com/backnotprop/plannotator --skill review-renovate

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs88
repo stars7.5k
Last updatedAugust 5, 2026
Repositorybacknotprop/plannotator

What it does

Review Renovate GitHub Actions PRs by verifying pinned SHAs against upstream tags and checking for breaking changes.

Who is it for?

Vetting Renovate GitHub Actions dependency PRs for supply-chain integrity

Skip if: Reviewing feature PRs or non-dependency code changes

When should I use this skill?

A Renovate PR updates GitHub Actions in .github/workflows/.

What you get

Each action's pinned SHA is verified against its upstream tag and a safe/do-not-merge verdict is given.

  • summary table of action version changes with SHA-verified status
  • safe-to-merge or do-not-merge recommendation

By the numbers

  • six-step review process
  • verifies both old and new SHAs per action

Files

SKILL.mdMarkdownGitHub ↗

Review Renovate GitHub Actions PRs

You are reviewing a Renovate bot PR that updates GitHub Actions dependencies. Your job is to verify supply chain integrity and ensure the upgrades won't break CI/CD workflows.

Inputs

You will be given a PR number or URL. Use gh CLI to fetch PR details and diff.

Steps

1. Fetch PR metadata and diff

gh pr view <PR> --json title,body,files,commits,author,headRefName
gh pr diff <PR>

Confirm the PR author is app/renovate. If not, flag this immediately — it may not be an automated dependency update.

2. Identify all action version changes

From the diff, extract each changed action:

  • Full action name (e.g., oven-sh/setup-bun)
  • Old version tag and pinned SHA
  • New version tag and pinned SHA
  • Update type (patch, minor, major)

3. Verify pinned SHAs against upstream tags

For every action being updated, verify both old and new SHAs match the claimed version tags:

gh api repos/{owner}/{repo}/git/ref/tags/{version} --jq '.object.sha'

Compare each result against the SHA in the workflow file. If any SHA does not match, stop and report a supply chain integrity failure. Do not approve the PR.

4. Review changelogs for breaking changes

From the PR body (Renovate includes release notes), check each updated action for:

  • Removed inputs or outputs that the workflows currently use
  • Changed default behavior for inputs the workflows rely on
  • New required inputs
  • Major version bumps (these almost always have breaking changes)

5. Check workflow compatibility

Read the affected workflow files and verify:

  • No removed or renamed inputs are being used
  • No changed defaults affect current behavior
  • The action's runtime requirements are still met (e.g., Node.js version compatibility)

6. Report findings

Present a summary table:

ActionOldNewTypeSHA verified
.........patch/minor/majoryes/NO

Then state:

  • Whether all SHAs are verified
  • Whether any breaking changes were found
  • Whether the workflows remain compatible
  • A clear safe to merge or do not merge recommendation

Related skills

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.