Skip to content
Back to skills

Updating Dependencies

ASecurity

Updating catalog dependencies to latest minor/patch versions

  • 9 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
code-quality

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add JacobLey/leyman --skill updating-dependencies --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Updating Dependencies?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Updating Dependencies
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jacobley-updating-dependencies/badge)](https://www.skillsdirectory.com/skills/jacobley-updating-dependencies)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: updating-dependencies
description: Updating catalog dependencies to latest minor/patch versions
---

# Updating Dependencies

All external versions live in the default `catalog:` in `pnpm-workspace.yaml`. Changing a version there changes it for every package.

By default only apply **minor/patch** updates. Only bump a **major** version when the user asked for that specific package, since it may be held back on purpose.

## Steps

1. **Find updates:** `pnpm outdated -r --format json`.
2. **Classify:** an update is minor/patch when the latest major equals the current major. For `0.x`, `0.7 → 0.8` counts as minor.
3. **Edit `catalog:`** in `pnpm-workspace.yaml` to `^<new-version>`. Leave the named `catalogs:` alone unless the package is already listed there.
4. **Changeset:** for each updated entry whose `dependencyType` is not `devDependencies`, collect its `dependentPackages[].name`, skipping packages under `leyman/`. Write one changeset (see [versioning](../versioning/SKILL.md)) with:
   - `minor` for packages where it is a `peerDependency` or `optionalDependency`
   - `patch` where it is a regular `dependency`

   Summary: `Update dependencies: <package@version, ...>`.
5. **Install:** `pnpm i`, then `pnpm outdated -r`. Only skipped majors (or nothing, for a requested major) should remain.
6. **Test:** `test-only`, then `test-and-fix` (adds lint + auto-fix). For a major bump, finish with `test-ci`.

Report any test or lint failures to the user instead of working around them. Small fixes are fine to propose, but anything needing a refactor is the user's call.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…