Skip to content
Back to skills

Fec Dependency Upgrade

ASecurity

Use when planning, implementing, or reviewing frontend dependency upgrades, package migrations, lockfile changes, major framework version bumps, CVE remediation, peer dependency conflicts, ESM/CJS shifts, build-tool compatibility, or CI verification matrices; Chinese triggers include dependency upgrades, version upgrades, lockfile, peer dependency, CVE fixes, major version migrations.

  • 21 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
developmenttypescriptgonodetestingrefactoringapifrontendsecuritydocumentation

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 3, 2026

npx -y skills add bovinphang/frontend-craft --skill fec-dependency-upgrade --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Fec Dependency Upgrade?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Fec Dependency Upgrade
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/bovinphang-fec-dependency-upgrade-frontend-craft/badge)](https://www.skillsdirectory.com/skills/bovinphang-fec-dependency-upgrade-frontend-craft)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: fec-dependency-upgrade
description: Use when planning, implementing, or reviewing frontend dependency upgrades, package migrations, lockfile changes, major framework version bumps, CVE remediation, peer dependency conflicts, ESM/CJS shifts, build-tool compatibility, or CI verification matrices; Chinese triggers include dependency upgrades, version upgrades, lockfile, peer dependency, CVE fixes, major version migrations.
---

# Dependency upgrade

Suitable for front-end dependency upgrades, bug fixes, major version migrations and lockfile risk reviews. Load [references/dependency-upgrade-workflow.md](references/dependency-upgrade-workflow.md) when you need specific processes and checklists.

## Purpose

Reduce disruptive changes, supply chain risks, and CI regressions by upgrading dependencies in a provenance-driven and small-batch verification manner.

## Procedure

1. Establish a baseline of truth: Read package manager, lockfile, Node version, workspace scope, CI commands, and current verification status.
2. Classified upgrade goals: security fixes, patch upgrades, minor version upgrades, major version migrations, framework migrations, build tool migrations, or dependency cleanup.
3. Verify sources: For version-sensitive libraries, read official release notes, migration guide, peer dependency, Node/browser support and deprecation items.
4. Split into smaller batches: Security patches can be processed centrally; large versions, build tools, frameworks and testing tools must be verified in separate batches.
5. Address compatibility boundaries: Check for ESM/CJS, TypeScript types, CSS handling, SSR/RSC, plugin APIs, peer dependencies, and polyfill changes.
6. Run the verification matrix: at least cover install, typecheck, unit/component tests, and build; for key applications, add E2E, Storybook, or manual smoke.
7. Synchronization documentation: Record upgrade reasons, versions, destructive changes, migration commands, rollback methods, and paths that still require manual verification.

## Constraints

- No more big version jumps without source and verification.
- Do not blindly upgrade critical runtime packages to eliminate audit warnings; first determine the exploitable paths and repair the impact.
- Avoid manual editing of lockfile to avoid dependency conflicts.
- Do not mix dependency upgrades and unrelated refactorings in one batch.
- Do not remove peer dependencies or build plugins unless proven not to be used by runtimes, subpackages or CIs.

## Expected Output

Output upgrade list, risk classification, source basis, batch strategy, modification scope, verification command, failure handling and rollback suggestions. After completion, the lockfile is consistent with the package manifest, key verification is passed, and destructive changes are recorded.

Files in this skill

  • SKILL.md2.8 KB
  • references/dependency-upgrade-workflow.md1.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…