version-api — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited version-api (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Implement versioning strategies for Rails APIs.
| Concern | File |
|---|---|
| Route namespaces | config/routes.rb |
| Header versioning | app/controllers/concerns/api_versioning.rb |
| Deprecation headers | app/controllers/concerns/deprecatable.rb |
| Compatibility specs | spec/requests/api/backward_compatibility_spec.rb |
GENERATED CODE SAFETY:
- NEVER generate code that constantizes or evaluates caller-supplied version strings
(e.g. "V#{params[:version]}".constantize is forbidden — use an explicit allowlist).
- NEVER generate code that passes request headers or paths unsanitized into class
instantiation, eval, or dynamic dispatch.
- Allowlist-only version resolution: generated routing/concern code MUST resolve
version identifiers from a fixed set (V1, V2, ...), not from free-form input.
ALWAYS maintain backward compatibility for at least one major version
NEVER remove endpoints without deprecation period
ALWAYS version in URL path (/api/v1/) or Accept header, never in body/api/v1/) for public APIs; Accept header for internal/private APIs. See strategies.md for header-based versioning details and trade-offs.namespace :v2 block in config/routes.rb: namespace :v1 do
resources :users
end
namespace :v2 do
resources :users
end module V2
class UsersController < V1::UsersController
def index
render json: User.all, only: [:id, :name, :email, :phone]
end
end
endSee EXAMPLES.md for additional inheritance patterns.
Deprecatable in old-version controllers to emit Sunset and Deprecation response headers automatically via a before_action: module V1
class UsersController < ApplicationController
include Deprecatable
# Override sunset_date on the class to set the retirement date:
# def self.sunset_date = Date.new(2025, 6, 1)
end
endbundle exec rspec spec/requests/api/backward_compatibility_spec.rb to confirm no regressions before merging.When asked to implement API versioning, your output MUST include:
Load these files only when their specific content is needed:
| Skill | When to chain |
|---|---|
| generate-api-collection | When generating the updated API endpoints |
| test-engine | When verifying specs for regressions |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.