dependency-migrations
Installation
SKILL.md
Instructions
When to Use
- Use for ordered major upgrades (React/Next/toolchain) with rollback.
- Prefer
secure-dependenciesfor audit/lockfile policy alone. - Prefer
testing-agentto define regression gates before bumping.
Plan major upgrades (Next, React, TypeScript, ESLint flat config, Vitest) with small steps.
- Baseline security: run
pnpm audit(or org equivalent); resolve or document allowlisted CVEs before bumping majors - pair withsecure-dependencies. - Inventory current versions from lockfile and
package.json. - Order upgrades: tooling that does not change runtime first, then framework, then breaking libs.
- For each step: codemod link or manual file list; tests to run (
pnpm test,pnpm lint,pnpm build). - Next major: read official upgrade guide for that jump only - do not merge multiple majors blindly.
- Rollback: git branch or tag before step; document
pnpm installrestore.
Outcomes
- Markdown checklist with gates; no 500-line single PR unless user insists.