Agent skill

Update Dependencies

by alorence in alorence/django-modern-rpc

Routine update of all project dependencies — uv itself, uv.lock (all groups), tool versions pinned in GitHub workflows and .pre-commit-config.yaml (uv, ruff, mypy...), and SHA-pinned GitHub Actions.

MITAuto-check passedDevelopment

Install Update Dependencies

skills CLI
$ npx skills add alorence/django-modern-rpc --skill update-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alorence/django-modern-rpc update-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alorence/django-modern-rpc.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/update-dependencies .claude/skills/update-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-dependencies
GitHub stars
111
Token cost
~1.3k tokens
SKILL.md length
574 words
Files
2 (incl. scripts)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Routine update of all project dependencies — uv itself, uv.lock (all groups), tool versions pinned in GitHub workflows and .pre-commit-config.yaml (uv, ruff, mypy...), and SHA-pinned GitHub Actions.

  • Works in 6 steps: Update uv locally → Update project dependencies → Propagate tool versions to CI and… → …
  • Asked to bump dependencies
  • SKILL.md covers 1. Update uv locally, 2. Update project dependencies, 3. Propagate tool versions to… and 4. Check GitHub Actions…, plus 2 more sections
  • Runs Python scripts from its folder; calls uv, git and python3; reaches github.com; needs GITHUB_TOKEN

What it does

Update Dependencies is an agent skill from alorence/django-modern-rpc. Routine update of all project dependencies — uv itself, uv.lock (all groups), tool versions pinned in GitHub workflows and .pre-commit-config.yaml (uv, ruff, mypy...), and SHA-pinned GitHub Actions. Use when asked to "bump dependencies", "update deps", "mettre à jour les dépendances" or similar.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/check_actions.py`).

It sits in Development, covering Linting and formatting, Type safety and CI/CD. It works with GitHub Actions, Ruff, Django and Python. The repository describes itself as: Simple XML-RPC and JSON-RPC server for modern Django. The licence is MIT.

When your agent uses it

  • Asked to bump dependencies
  • Mettre à jour les dépendances

Example prompts

  • “bump dependencies”
  • “update deps”
  • “mettre à jour les dépendances”
  • “/update-dependencies”

Requirements

  • Python 3
  • A credential in GITHUB_TOKEN

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Update uv locally
  2. Update project dependencies
  3. Propagate tool versions to CI and pre-commit
  4. Check GitHub Actions versions and SHA pins
  5. Verify
  6. Summarize

What it can do on your machine

Read from SKILL.md and the folder at commit 469c203. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • uv
    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Dependencies loads about 1.3k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 574 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from alorence/django-modern-rpc at commit 469c203, republished under its MIT licence (© alorence). 574 words, ~1,306 tokens.

Download SKILL.mdSave it as .claude/skills/update-dependencies/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
update-dependencies
description
Routine update of all project dependencies — uv itself, uv.lock (all groups), tool versions pinned in GitHub workflows and .pre-commit-config.yaml (uv, ruff, mypy...), and SHA-pinned GitHub Actions. Use when asked to "bump dependencies", "update deps", "mettre à jour les dépendances" or similar.

Update dependencies

Routine maintenance task. Past examples: commits 7907fcb, 944ca20, f32cd43 (git show <sha> -- .github .pre-commit-config.yaml). Files usually touched: uv.lock, .github/workflows/*.yml, .pre-commit-config.yaml.

Start from a clean working tree (git status). If it is not clean, ask the user before going further.

1. Update uv locally

bash
uv self update
uv --version   # remember this version: it is the target for UV_VERSION and the uv-pre-commit rev

If uv self update fails (uv installed by a system package manager), report it and use the version reported by uv --version, after checking the latest release on https://github.com/astral-sh/uv/releases.

2. Update project dependencies

bash
git diff --quiet uv.lock  # sanity check: lockfile untouched before update
uv sync --upgrade --all-groups

Then list what changed, to know which tools must be propagated elsewhere:

bash
git diff uv.lock | grep -E '^[-+](name|version) = ' | paste - - | head -100

A more readable alternative: uv tree --outdated before the update, or compare uv pip list before/after.

3. Propagate tool versions to CI and pre-commit

Find every hard-coded tool version outside uv.lock:

bash
grep -nE '_VERSION:|rev:' .github/workflows/*.yml .pre-commit-config.yaml

Known locations (check again with the grep above, new ones may appear):

ToolLocationTarget version
uvenv.UV_VERSION in tests.yml, benchmarks.yml, publish.ymluv --version (step 1)
uvastral-sh/uv-pre-commit rev: in .pre-commit-config.yamlsame, without v prefix (0.12.15)
ruffastral-sh/ruff-pre-commit rev:ruff version in uv.lock, with v prefix (v0.16.8)
mypypre-commit/mirrors-mypy rev:mypy version in uv.lock, with v prefix
ty, othersany *_VERSION variable or rev: added laterversion in uv.lock

Get a locked version with: grep -A1 '^name = "ruff"$' uv.lock.

Rules:

  • Pre-commit hooks for tools that are also project dependencies must match the version in uv.lock exactly (don't use pre-commit autoupdate for them, it may pick a version newer than the lock).
  • For hooks that are not project dependencies (e.g. pre-commit/pre-commit-hooks), check the latest release with git ls-remote --tags --sort=-v:refname https://github.com/<owner>/<repo> | head and update if needed.
  • If a pre-commit mirror has not yet published a tag for the locked version, keep the previous rev and tell the user.
Show full SKILL.md (296 more words)Show less

4. Check GitHub Actions versions and SHA pins

Run the helper script (stdlib only, uses GitHub API + git ls-remote):

bash
python3 .claude/skills/update-dependencies/scripts/check_actions.py

It lists every uses: and, per action, the latest release tag and the commit SHA it points to:

  • [OK]: pinned SHA is the latest release, nothing to do.
  • [OUTDATED]: replace the SHA and the version in the trailing comment, everywhere the action is used (e.g. sed -i 's/<old_sha>/<new_sha>/g; s/# v10.1.0,/# v10.2.0,/g' .github/workflows/*.yml). Keep the existing comment format of each line (# vX.Y.Z - <releases url> or # vX.Y.Z, see <releases url>).
  • [NOT PINNED (tag ref)] (e.g. actions/checkout@v6, github/codeql-action/*@v4): report to the user when a new major version exists (e.g. v6 → v7), and ask whether to bump the major tag or to pin to a SHA. Don't change these silently.

Caveats:

  • "Latest release" is not always meaningful: github/codeql-action publishes codeql-bundle-* releases, so compare with tags (git ls-remote --tags https://github.com/github/codeql-action 'v4*') instead.
  • For a major version bump of a pinned action, look at the release notes for breaking changes (inputs renamed, Node runtime change...) and mention them to the user.
  • If the API rate limit is hit, export GITHUB_TOKEN or fall back to git ls-remote per repository.

Re-run the script after editing: every pinned action must be [OK].

5. Verify

bash
uv lock --check
uv run ruff check .
uv run ruff format . --check
uv run --group=type-checking mypy
uv run --group=type-checking ty check .
uv run pytest -n auto

A new ruff/mypy/ty version may introduce new lint or typing errors. Fix trivial ones (or auto-fix with uv run ruff check . --fix); for anything non-trivial, report to the user instead of silencing rules.

6. Summarize

Report to the user:

  • uv version before → after
  • notable package updates (major/minor bumps, especially Django, ruff, mypy, ty, serialization backends)
  • updated actions (old → new version)
  • unpinned actions with a new major available, and any skipped item with the reason
  • verification results (tests, lint, type checking)

Don't commit unless asked. Past commit messages: Bump all dependencies / Bump dependencies.

© alorence, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in .claude/skills/update-dependencies of alorence/django-modern-rpc.

  • SKILL.md
  • scripts/check_actions.py

Open the folder on GitHubat commit 469c203

Compare with similar skills

Update Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Dependencies this skillalorence/django-modern-rpc111—~1.3kAutomated safety check: PassMIT
Python Pypi Package Buildergithub/awesome-copilot40k1 repos~4.6kAutomated safety check: PassMIT
Python Rulessoftspark/ai-toolkit179—~2.9kAutomated safety check: PassApache-2.0
Simple Modern Uvjlevy/simple-modern-uv301—~1.9kAutomated safety check: PassMIT
Python Idiomsirahardianto/awesome-agv157—~4.4kAutomated safety check: PassMIT
Pythonericrisco/rsc-harness174—~3.8kAutomated safety check: PassMIT

Similar skills

  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    DevelopmentAuto-check passed
  • Python Rules

    softspark/ai-toolkit

    Python coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Simple Modern Uv

    jlevy/simple-modern-uv

    Start, selectively modernize, fully migrate, or update Python projects using simple-modern-uv practices: uv, ruff, BasedPyright, pytest, GitHub Actions CI, and tag-driven PyPI publishing.

    301 GitHub stars~1.9k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Python Idioms

    irahardianto/awesome-agv

    Modern Python (3.11+) idioms: type annotations, typing Protocols, Pydantic models, asyncio, pytest fixtures, and Ruff/Mypy strict compliance.

    157 GitHub stars~4.4k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Python

    ericrisco/rsc-harness

    A skill your agent uses when the task is Python itself, in any framework or none: PEP 695 generics, mypy --strict typing, dataclass/Protocol/TypedDict/Enum choices, asyncio.TaskGroup, stdlib idioms…

    174 GitHub stars~3.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Run And Verify

    aropan/clist

    Choose and run focused checks after changing CLIST Python code: Django tests, standalone pytest tests, offline parser fixtures, Ruff, or a relevant management-command check.

    439 GitHub stars~461 tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

Questions about Update Dependencies

What does Update Dependencies do?

Routine update of all project dependencies — uv itself, uv.lock (all groups), tool versions pinned in GitHub workflows and .pre-commit-config.yaml (uv, ruff, mypy...), and SHA-pinned GitHub Actions. Update Dependencies is an agent skill from alorence/django-modern-rpc.), and SHA-pinned GitHub Actions.

When should I use Update Dependencies?

Update Dependencies fits situations like: asked to bump dependencies; mettre à jour les dépendances.

How do I install Update Dependencies in Claude Code?

Run `npx skills add alorence/django-modern-rpc --skill update-dependencies -a claude-code`. Or copy the skill folder (.claude/skills/update-dependencies in alorence/django-modern-rpc) into .claude/skills/update-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Update Dependencies in Codex?

Run `npx skills add alorence/django-modern-rpc --skill update-dependencies -a codex`. Or copy the skill folder (.claude/skills/update-dependencies in alorence/django-modern-rpc) into .agents/skills/update-dependencies in your project. Codex loads it when a task matches its description.

Can I use Update Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alorence/django-modern-rpc --skill update-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-dependencies, .gemini/skills/update-dependencies, .github/skills/update-dependencies and .opencode/skills/update-dependencies in your project.

What does Update Dependencies need to run?

Going by SKILL.md and its folder, Update Dependencies needs Python for the scripts in its folder, the command-line tools its instructions call (uv, git and python3) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; A credential in GITHUB_TOKEN.

Does Update Dependencies access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Update Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Update Dependencies use?

Update Dependencies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Dependencies use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Dependencies?

Skills that share tags, products or a category with Update Dependencies: Python Pypi Package Builder (github/awesome-copilot, 40k stars), Python Rules (softspark/ai-toolkit, 179 stars), Simple Modern Uv (jlevy/simple-modern-uv, 301 stars) and Python Idioms (irahardianto/awesome-agv, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Dependencies?

alorence (a GitHub user) maintains it in alorence/django-modern-rpc, which has 111 GitHub stars. The repository was last updated on October 7, 2026.

Source: alorence/django-modern-rpc on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.