ln-32-dependency-upgrader

Installation
SKILL.md

Dependency Upgrader

Goal: Upgrade dependencies in small, attributable batches. Preserve manifests, lockfiles, runtime support, and product behavior; do not treat a newer version as valuable without compatibility, security, or maintenance evidence.

Execution contract: The ordered checkboxes are the Definition of Done. Track every item internally as PENDING, PROVEN with concrete evidence, CLEARED with evidence that its condition is absent, or UNPROVEN with a gap; reading, delegation, or tool failure is not proof. Reconcile items after each section. Before returning, resolve all PENDING and count only PROVEN and CLEARED; apply the skill's verdict and approval rules to every gap. Preserve user intent, scope, and existing authorization. Continue authorized work; ask only for consequential unresolved choices or required external approval. Scale depth to material risk without silently skipping checks. Preserve dependency and safety ordering; otherwise choose the verification method appropriate to each obligation.

Tool Routing

Need Preferred tool Use it when Fallback
Package-manager detection Manifests, lockfiles, workspace files, runtime files, and repository instructions Always before choosing commands or update scope Build and CI configuration
Outdated and vulnerable packages Native package-manager outdated and audit commands The manager and registry are available Official registry, vendor advisory, and lockfile inspection
Breaking changes and support Official release notes, migration guides, changelogs, advisories, and runtime support tables Every consequential minor, major, replacement, or security update Primary-source repository releases; otherwise mark UNVERIFIED
Usage and blast radius Language server or host-native code intelligence An updated API, type, plugin, build tool, or runtime may affect consumers Targeted import, symbol, configuration, and script search
Safe version changes Native package-manager commands Updating manifests and generated lock state Do not hand-edit lockfiles or emulate package resolution
Verification Repository-defined install, restore, build, lint, type, test, migration, and smoke commands Before changes and after each batch CI and script inspection with explicit unverified status
Diff and rollback Git status, diff, and isolated commits or worktree Protecting user changes and reverting only the failed batch Stop if the batch cannot be isolated safely
Installs
49
GitHub Stars
559
First Seen
Jul 13, 2026
ln-32-dependency-upgrader — levnikolaevich/claude-code-skills