skills/dependency-upgrade/SKILL.md
Use this skill when upgrading dependencies with risk-aware batching, compatibility checks, lockfile review, migration notes, and verification steps for routine updates or major-version changes.
npx skillsauth add chatandbuild/skills-repo Dependency UpgradeInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Update dependencies methodically so security and compatibility improve without destabilizing delivery.
npm outdated for overview; npx npm-check-updates -u (or ncu -u) for targeted bumps. Use --target minor or --target patch to avoid majors. Apply in batches and run tests between batches.pip-compile (from pip-tools) to regenerate requirements.txt from requirements.in. Bump packages in .in, then pip-compile to resolve. Prefer virtualenv per project.cargo update updates lockfile within semver; cargo upgrade (cargo-edit) for version bumps in Cargo.toml. Run cargo test and cargo clippy after each batch.group:non-major for minor/patch, separate group for majors). Use schedule and assignees to control review load. Enable automerge only for low-risk groups (e.g., devDeps, lockfile-only).Group by risk level:
Avoid mixing framework upgrades (e.g., React) with library upgrades in the same batch; framework changes often cascade.
react-codemod, ember-cli-update) or custom scripts. Run on a branch; review diffs before committing.overrides/resolutions sparingly; prefer upgrading the consumer or finding compatible versions.Return:
git revert, lockfile restore) if issues appear post-merge.tools
Use only when the user explicitly asks to stage, commit, push, and open a GitHub pull request in one flow using the GitHub CLI (`gh`).
development
Use this skill any time a spreadsheet file is the primary input or output. This means any task where the user wants to: open, read, edit, or fix an existing .xlsx, .xlsm, .csv, or .tsv file (e.g., adding columns, computing formulas, formatting, charting, cleaning messy data); create a new spreadsheet from scratch or from other data sources; or convert between tabular file formats. Trigger especially when the user references a spreadsheet file by name or path — even casually (like "the xlsx in my downloads") — and wants something done to it or produced from it. Also trigger for cleaning or restructuring messy tabular data files (malformed rows, misplaced headers, junk data) into proper spreadsheets. The deliverable must be a spreadsheet file. Do NOT trigger when the primary deliverable is a Word document, HTML report, standalone Python script, database pipeline, or Google Sheets API integration, even if tabular data is involved.
development
Use this skill when turning messy workout information into clear logs, comparing user-provided sessions, surfacing trends or likely PRs, and suggesting realistic next-session steps.
tools
Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs.