Agent skill

update-dependencies

Smart dependency updates across ecosystems (npm/bun/pnpm, uv/poetry, cargo).

9 files · 31.6 KB · Source ↗ · Raw SKILL.md · Markdown directory · Download skill.tgz

Copy the prompt. Paste it into your agent.

Verify the bytes and inspect the files before trusting a skill. A matching hash is not a safety review.

Read the install prompt
Full inline prompt for offline use

Includes SKILL.md. Supporting files still require a download.

Install from a shell

Run this in a terminal. It downloads the pinned archive, checks its SHA-256 digest, and extracts it into ~/.claude/skills, where Claude Code loads skills. For Codex and other agents that read ~/.agents/skills, edit the SKILLS_DIR line. If the skill is already installed, the command stops and changes nothing.

Dependency Updater

Smart dependency management with security-first prioritization, intelligent batching, and learning from outcomes.

Ecosystem Detection

First, detect the project's ecosystem:

# Check for lockfiles (in priority order)
ls bun.lock bun.lockb pnpm-lock.yaml package-lock.json uv.lock poetry.lock Cargo.lock 2>/dev/null | head -1
Lockfile Ecosystem Reference
bun.lock / bun.lockb npm (bun) npm.md
pnpm-lock.yaml npm (pnpm) npm.md
package-lock.json npm npm.md
uv.lock Python (uv) python.md
poetry.lock Python (poetry) python.md
Cargo.lock Rust cargo.md

Load the appropriate ecosystem reference for detailed commands.


Workflow

Phase 1: Security Audit

Run security check first. Security issues always take priority.

See ecosystem reference for specific audit command.

Categorize by severity:

Phase 2: Outdated Analysis

Check for outdated dependencies.

Categorize by update type:

Phase 3: Check History

Before major updates, check if we've updated this package before. Paths below are relative to this skill's base directory:

grep "<package-name>" data/outcomes.jsonl

Learn from past outcomes:

Phase 4: Risk Assessment

For packages with major bumps or unknown risk, fetch changelogs.

Score each update 1-5. See risk-assessment.md for guidelines.

Phase 5: Smart Grouping

Group related packages together. See grouping-strategies.md for patterns.

Priority order:

  1. Security fixes (own group, merge first)
  2. Ecosystem batches (related packages together)
  3. Low-risk patches (all together)
  4. Individual major updates

Phase 6: Execute Updates

For each group:

  1. Create branch: deps/<group-name>-$(date +%Y%m%d)
  2. Apply updates (see ecosystem reference)
  3. Run tests
  4. If tests fail: identify problematic package, exclude, continue

Phase 7: Create PR

Use format from pr-format.md.

git add <lockfile> <manifest>
git commit -m "deps: <type> update <group-name>"
git push -u origin HEAD
gh pr create --title "deps: <type> update <group-name>" --body-file -

Phase 8: Log Outcome

After PR is merged (or if update fails), log the outcome:

bun scripts/log-outcome.ts

The script will:

  1. Pre-fill: date, project, ecosystem, packages, versions
  2. Prompt for: outcome (success/failed/required_migration) and notes
  3. Append to data/outcomes.jsonl

Command Options

When invoked via /update-dependencies:

Option Effect
security only Only fix security vulnerabilities
plan Enter plan mode - analyze and design update strategy for approval
major Include major version updates
group <name> Update specific ecosystem group
--check-history Show past outcomes for packages being updated

Quick Start

# Run the analyzer first
bun scripts/analyze.ts

# Or invoke the skill
/update-dependencies plan    # Analyze and plan
/update-dependencies         # Full execution

Error Recovery

If update fails partway:

Files