---
title: "deps-flow"
description: "Autonomous Dependabot queue management: the one maintainerd plugin that merges. The dependabot skill gates every bot-authored dependency PR on all checks green, no requested changes, and a configured semver policy (patch"
canonical: https://agentpluginsdirectory.com/plugins/deps-flow
last-updated: 2026-10-08
---

# deps-flow
Autonomous Dependabot queue management: the one maintainerd plugin that merges. The dependabot skill gates every bot-authored dependency PR on all checks green, no requested changes, and a configured semver policy (patch/minor by default, majors held for the human), merges one PR per non-overlapping file group per pass, waits for Dependabot to rebase the rest (nudging with @dependabot rebase only when a rebase is genuinely stuck), and repeats until the queue drains. It never fixes a broken update: it diagnoses the CI failure, files one issue with the evidence, labels the PR blocked, and moves on. Install only in repos where a bot is allowed to merge; every knob lives in.claude/maintainerd.json's depsFlow block.
- Slug: deps-flow
- Publisher: Allen Hutchison
- Repository: https://github.com/Vycari/maintainerd
- Manifest: plugins/deps-flow/plugin.json
- Version: 0.2.26
- License: MIT
- Category (editorial): devops-cloud
- Skills: 1 (dependabot)
- MCP servers: 0
- Stars: 3
- Repository created: 2026-06-28
- Repository last pushed: 2026-10-08
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/deps-flow
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What deps-flow does, in the publisher's words

Drains the Dependabot queue unattended.

> This is the exception to the suite's "never auto-merges" rule. Every other maintainerd skill > stops at the merge gate. dependabot merges dependency PRs that pass a strict gate, all checks > concluded green, no requested changes, bump level within your policy. It requires an explicit > depsFlow.enabled: true; an absent config block means off, never defaults.

Run /dependabot dry-run first. It executes the full tick read-only and prints exactly what a live run would do.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/Vycari/maintainerd/HEAD/plugins/deps-flow/README.md

## Skills

- dependabot: Drain the repo's Dependabot queue safely: gate every bot-authored dependency PR on all checks green, no requested changes, and the repo's semver policy (patch/minor by default; majors held for the human), merge one PR per non-overlapping file group, wait for Dependabot to rebase the rest, and repe…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
