update-deps
Update Deps
Update a project's npm dependencies the safe way: in small, themed, version-locked groups, applied one group at a time, where each group is verified against the app before it is committed. A group that breaks the app is rolled back, not left half-applied. The whole point is that you never end up in a state where many packages moved at once and you can't tell which one broke the build — every commit in the history is a known-good checkpoint.
Reference files:
- references/grouping.md — how to group packages into version-locked families. Read this before grouping.
- references/report-template.md — the exact shape of the final report. Read this before writing the report.
Why grouping matters (read this first)
Thematic grouping isn't cosmetic — it's a correctness requirement. Families like @storybook/*, vitest +
@vitest/*, react + react-dom + @types/react, or next + eslint-config-next are version-locked to each
other: bump one without the others and the build fails on a peer-version mismatch even though each individual package
"installed fine." So the rule is: