# Weekly dependency security check

Once a week, the agent checks your dependencies against new security advisories and opens upgrade pull requests.

## What to tell your agent

```text
Every Monday, check the dependencies in my repositories against new security advisories. For each advisory that affects us, open a pull request that upgrades to a fixed version and note the risk and any breaking changes. Do not add new packages without asking, and do not merge anything. Finish with one summary message.
```

## How it runs

- List dependencies across your repositories
- Match them against new advisories
- Open upgrade pull requests with notes
- Send one weekly summary

## Watch out for

- Upgrades can break things, so read the breaking-change notes before merging
- New packages are a supply-chain risk, so keep installs behind approval

## What you get

One weekly message and a ready upgrade pull request for every advisory that matters.
