chore(skills): add pg-security-release-analysis Claude Code skill#2169
Merged
utkarash2991 merged 1 commit intoMay 26, 2026
Merged
Conversation
PostgreSQL Extension Dependency Analysis: PR #2169
SummaryNo extensions had dependencies with MAJOR version updates. Full Analysis ResultsPostgreSQL 15 Extension DependenciesPostgreSQL 17 Extension DependenciesOrioleDB 17 Extension Dependencies |
PostgreSQL Package Dependency Analysis: PR #2169
SummaryNo packages had MAJOR version updates. Full Analysis ResultsPostgreSQL 15 Dependency ChangesExtracting PostgreSQL 15 dependencies...
Runtime Closure Size
Raw Dependency ClosurePostgreSQL 17 Dependency ChangesExtracting PostgreSQL 17 dependencies...
Runtime Closure Size
Raw Dependency Closure |
Automates the recurring analysis for PG quarterly security releases. Structured around 11 classes of issue (privilege tightenings, silent data correctness, memory safety, tool-side fixes, ABI breaks, plan shifts, etc.) with detection commands and Supabase-impact questions per class, plus an explicit Supabase Surface Map to cross-check findings against. Captures critical universal gotchas (don't trust git log --grep for "first landed in X" — use git tag --contains <sha>; CVSS in commit messages diverges from postgresql.org/support/security) so they don't have to be rediscovered each cycle. Introduces .claude/skills/ to supabase/postgres (first skill in this repo). Worked example used to derive the workflow: PSQL-1110 (May 2026 cycle). Refs: PSQL-1110, PSQL-1258
38ad123 to
af6ad1c
Compare
samrose
approved these changes
May 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce?
Adds a Claude Code skill at
.claude/skills/pg-security-release-analysis/SKILL.mdfor analyzing upstream PostgreSQL quarterly security releases. First skill in this repo, so the PR also introduces the.claude/skills/convention here.What is the current behavior?
Each PG quarterly security release requires 1–2 days of manual analysis to:
postgresql.org/support/security/Pitfalls had to be rediscovered each cycle. The May 2026 cycle initially misclassified 5 CVE severities, attributed 4 commits to wrong landing versions, and missed a non-CVE intarray bug — all from re-deriving the process without a runbook. Tracked in PSQL-1110.
What is the new behavior?
A skill that walks the analyst through the workflow, structured around:
git log --grepfor "first landed in X")shared_preload_libraries, customer roles, backup tooling, libpq-linking services, etc. — so cross-checking is comprehensive, not implicit.The 11 classes cover:
Skill is invoked automatically by Claude Code when the user asks about analyzing a PG security release (description-triggered match).
Additional context