deps-refresh
Installation
SKILL.md
Dependency Refresh
A routine "bring it up to date" pass on a data-fair service (npm workspaces + an alpine node docker image). The order is fixed: measure, security, free wins, majors you can prove are safe, then a written plan for the rest. Much of the value is in what you decline to upgrade, and why.
Phase 1 — Measure before touching anything
Two scanners, because they see different things:
npm audit # whole tree, dev included
npm audit --omit=dev # what actually ships
npm outdated --workspaces --include-workspace-root
docker pull ghcr.io/data-fair/<service>:<version> # the released image
trivy image --scanners vuln ghcr.io/data-fair/<service>:<version>
Trivy on the built image is not redundant with npm audit. It sees the alpine OS layer, which is usually where the criticals are, plus the npm bundled in the node base image, and it reports only what is actually shipped. npm audit sees the dev tree that never reaches production. Neither alone is a security answer.
Record the before numbers; they go in the PR.