Skip to content
Back to skills

Dependency Update

ASecurity

Bump dependencies safely, regenerate the lockfile, and confirm the test suite still passes

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 3, 2026
ai-agentsgogit

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned September 3, 2026

npx -y skills add black141312/ada --skill dependency-update --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dependency Update?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dependency Update
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-dependency-update/badge)](https://www.skillsdirectory.com/skills/black141312-dependency-update)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dependency-update
description: Bump dependencies safely, regenerate the lockfile, and confirm the test suite still passes
category: dependencies
---

# Dependency Update

Reach for this when bumping one or many dependencies and you want to land the change without breaking the build.

1. Snapshot the current state: note the green test/build baseline and capture the manifest + lockfile in git so you can diff later.
2. List what is outdated (`npm outdated`, `pip list --outdated`, `cargo update --dry-run`) and separate patch/minor from major bumps.
3. Bump in small batches — patches and minors first, one risky major at a time — and regenerate the lockfile deterministically.
4. Read the changelog/release notes for any major bump and apply required code or config migrations.
5. Run install clean (`npm ci`, `pip install -r` in a fresh venv) plus the full test suite and a build.
6. Commit the manifest and lockfile together with a message naming the packages and version ranges.

## Rules
- Never edit the lockfile by hand — let the package manager regenerate it.
- Pin majors and review them individually; a batched major bump hides which one broke things.
- Run a clean install, not an incremental one, so a stale cache doesn't mask a resolution problem.
- If tests fail, bisect the batch rather than reverting everything; isolate the offending package.
- Keep manifest and lockfile changes in the same commit so CI never sees a drifted pair.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…