targets/amp/skills/phx-deps-update/SKILL.md
Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo). Use to upgrade/bump Elixir dependencies or when versions fall behind. NOT for deps.get failures (phx-investigate).
npx skillsauth add oliver-kriska/claude-elixir-phoenix phx-deps-updateInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Inventory → update → fix breaks → grouped PRs. This is the only MUTATING
deps skill: it edits mix.exs, mix.lock, and source. Security scanning
stays in phx-deps-audit; the vet ledger stays in phx-deps-vet.
phx-deps-update # inventory + interactive scope pick
phx-deps-update --scope patch # bundle all patch bumps, one PR
phx-deps-update --pkg phoenix_live_view # one package (+ coupled group)
phx-deps-update --dry-run # inventory only, no changes
mix.exs edit —
mix deps.update stays within requirements. Edit the constraint first;
add override: true only when mix hex.outdated <pkg> shows a
transitive consumer blocking. One major per PRdeps/<pkg>/CHANGELOG.md, then delta via mix hex.package diff. Never
update blindphx-verify (compile --warnings-as-errors + test). "Compiles" ≠ "works"references/coupled-groups.md)mix.lock + mix.exs edits + (for
Phoenix-family) assets/package-lock.json in ONE commitphx-deps-audit — run it on the lock diff
before any PR; don't reimplement audit ruleshex.outdated exit 1 is normal — it means "deps are outdated", not
failure. Capture with || trueRead mix.exs: deps list, umbrella (apps_path:), git/path deps, private
orgs (organization:/repo: in tuples), Phoenix/Ash presence. Create
scratch dir .claude/deps-update/{YYYY-MM-DD}/.
mix hex.outdated --all || true — parse the text table (no JSON exists;
see references/update-mechanics.md). Classify each
row patch/minor/major by semver delta; Update not possible = blocked
major (mix.exs constraint). Write inventory.md to scratch. Render
grouped table: Patch / Minor / Major / Blocked / Git-deps (manual).
--dry-run stops here.
Present groups with counts and risk. Default recommendation: "Patches (N)
— low risk, bundle into one PR". --scope/--pkg flags skip the prompt.
When ≥2 members of a coupled group are outdated, force them into one step
even under a narrower scope.
For each selected package, in coupled-group order:
deps/<pkg>/CHANGELOG.md → scratch/before/mix deps.update <pkg> [coupled...];
major: edit mix.exs constraint (+ override: true if needed), then
mix deps.update <pkg>git diff mix.lock → the REAL {pkg, old, new} set (hex.outdated says
what could change; the lock diff says what did)mix hex.package diff <pkg> <old>..<new> — keep the
CHANGELOG hunk. Empty → gh api repos/{o}/{r}/releases fallback →
compare-URL note (see references/changelog-sources.md)scratch/{pkg}-{old}-{new}.mdassets/package.json exists →
npm install --prefix assets, stage assets/package-lock.json with
the same commitRun phx-verify. On failure → Phase 5; else Phase 6.
Read the changelog deltas for "breaking"/"removed"/"deprecated" + the compile/test errors. Fix source (apply the sibling-file check). Re-verify.
Run phx-deps-audit on the working mix.lock diff (its Mode B default).
BLOCK findings → surface and offer phx-deps-vet <pkg> <ver> for
accepted risks. Never skip this before a PR.
Apply the splitting strategy (references/pr-strategy.md):
patches bundled, minors by area, majors solo, coupled groups always
together. PR bodies cite the changelog excerpt, the
https://diff.hex.pm/diff/<pkg>/<old>..<new> link, verification result,
and the deps-audit risk band. Stage lock + mix.exs + package-lock together.
phx-deps-update (mutating) → phx-deps-audit (security, Mode B)
│ │ BLOCK → phx-deps-vet (ledger)
└→ phx-verify (gate) → grouped commits / PRs
references/update-mechanics.md — hex.outdated parsing, update vs unlock+get, majors, lock-diffreferences/changelog-sources.md — hex.package diff, gh fallbacks, private orgsreferences/coupled-groups.md — must-move-together groups + edge casesreferences/pr-strategy.md — grouping rules, area buckets, PR template, scratch layouttools
Compatibility alias for the Elixir/Phoenix plugin's LiveView assigns audit. Invoke explicitly with /lv:assigns.
development
Trace Elixir call trees from entry points via mix xref. Use when debugging data flow, planning signature changes, or understanding how a bug reaches code.
tools
Compatibility alias for the Elixir/Phoenix plugin's N+1 query checker. Invoke explicitly with /ecto:n1-check.
tools
Compatibility alias for the Elixir/Phoenix plugin's Ecto constraint debugger. Invoke explicitly with /ecto:constraint-debug.