Dependency status
Bumps are proposed only — never auto-merged, never auto-floated.
Review the linked changelog, update the pin in its real location, and —
for an IG Publisher bump — recompute the jar's SHA-256 next to the new
version. Steps: docs/recipes/review-a-dependency-update.md.
The skill-catalog row is bumped with scripts/sync-skills.sh --ref vX.Y.Z,
which re-vendors skills/ and rewrites skills-lock.json in one diff.
Read the catalog's CHANGELOG.md first: a skill can be deprecated or
removed between releases.
pin not found rows are expected until the file/workflow that carries
the pin has landed; they are a reminder, not an error. not yet published on the template package is expected until the IG template's first
release reaches a registry.
THO / Extensions Pack — lockstep with meta
- ⚠️ HL7 Terminology (THO): module pins hl7.terminology.r4@7.3.0 but meta 2027.0.0-ballot.rc3 ships hl7.terminology.r4@7.1.0 — align the module's pin (meta is the family's source of truth).
- ⚠️ HL7 Extensions Pack: module pins hl7.fhir.uv.extensions.r4@5.3.0 but meta 2027.0.0-ballot.rc3 ships hl7.fhir.uv.extensions.r4@5.2.0 — align the module's pin (meta is the family's source of truth).
Dependency status
de.medizininformatikinitiative.template#ig-template— not a version pin (vendored/floating); see docs/recipes/switch-template-to-published.mdforschungsgruppe-digital-health/agent-skills(vendored skills)de.basisprofil.r4de.medizininformatikinitiative.kerndatensatz.metahl7.fhir.uv.crmihl7.fhir.uv.xver-r5.r4sushi-config.yaml)hl7.terminology.r4hl7.fhir.uv.extensions.r4de.medizininformatikinitiative.kerndatensatz.molgende.medizininformatikinitiative.kerndatensatz.icude.medizininformatikinitiative.kerndatensatz.studiede.medizininformatikinitiative.kerndatensatz.basede.medizininformatikinitiative.kerndatensatz.medikationTHO / Extensions Pack — lockstep with meta