Agent skill

Validator Dependency Upgrade

by express-validator in express-validator/express-validator

Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.

MITAuto-check passedDevelopment

Install Validator Dependency Upgrade

skills CLI
$ npx skills add express-validator/express-validator --skill upgrade-validator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install express-validator/express-validator upgrade-validator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/express-validator/express-validator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/upgrade-validator .claude/skills/upgrade-validator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upgrade-validator
GitHub stars
6.2k
Token cost
~1.2k tokens
SKILL.md length
448 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.

  • Works in 4 steps: Upgrade the package → Map upstream changes to this codebase → Declarations → …
  • Bumping validator to a newer release inside the express-validator repository
  • SKILL.md covers Policy: why upgrades are manual, Before you start, 1. Upgrade the package and 2. Map upstream changes to…, plus 3 more sections
  • Calls npm

What it does

express-validator holds the validator dependency to patch-only semver so an unexpected upstream minor release cannot slip in, which makes each bump a deliberate maintainer task. The workflow notes the previous version from package.json, runs npm install validator@latest, and if npm rewrites the range with a caret, changes it back to a tilde range to match the project's convention.

Next it maps upstream changes onto the codebase, using a tag-range compare on the validator.js repository and its changelog rather than commit titles alone. For each new validator it adds a signature to src/chain/validators.ts and an implementation to src/chain/validators-impl.ts, both in alphabetical order and delegating through addStandardValidation like neighboring methods; new sanitizers get a matching entry in src/chain/sanitizers.ts. The description also lists option types and declarations/validator.d.ts among the files kept in step.

When your agent uses it

  • Bumping validator to a newer release inside the express-validator repository
  • Adding chain methods for validators or sanitizers that are new in validator.js
  • Keeping declarations/validator.d.ts aligned with the upstream package

Example prompts

  • “Upgrade validator to the latest release and add any new chain methods it brings.”
  • “What changed upstream between our current validator version and the newest one, and which chain files need new methods?”
  • “Update declarations/validator.d.ts for the validator upgrade and confirm package.json still uses a tilde range.”

Requirements

  • npm
  • A checkout of the express-validator repository

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Upgrade the package
  2. Map upstream changes to this codebase
  3. Declarations
  4. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit 48d44de. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validator Dependency Upgrade loads about 1.2k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 448 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from express-validator/express-validator at commit 48d44de, republished under its MIT licence (© express-validator). 448 words, ~1,161 tokens.

Download SKILL.mdSave it as .claude/skills/upgrade-validator/SKILL.md (or your agent's skills folder).
name
upgrade-validator
description
Upgrades the npm `validator` dependency and syncs express-validator chain types, implementations, options, and `declarations/validator.d.ts` with validator.js releases. Express-validator intentionally pins `validator` to patch-only semver (see PR

upgrade-validator

Policy: why upgrades are manual

This project does not float on arbitrary new minor lines of validatorjs/validator.js. As described in express-validator#1253, the validator dependency is pinned to patch (e.g. ~x.y.z) so a new minor from upstream cannot be pulled in implicitly and surface mistaken or unexpected breaking changes. Bumping validator is a deliberate maintainers’ task: run this workflow, sync types and chain APIs, test, and ship.

After npm install, keep package.json consistent with that policy (typically ~<resolved-version>, not a loose ^ on the major/minor line unless the project explicitly changes policy).

Before you start

  • Record the previous validator version from package.json (and confirm after upgrade from package.json / lockfile).
  • The source of truth for what changed is validatorjs/validator.js. Use a tag range compare (e.g. v<old>...v<new>) to see commits and the diff between versions.

1. Upgrade the package

From the repo root, install the latest validator in-range and persist it to package.json / the lockfile:

bash
npm install validator@latest

If npm rewrites the range to ^ and the project uses patch-only pinning per #1253, change the dependency to ~<version> to match the previous convention.

2. Map upstream changes to this codebase

For each new validator, sanitizer, or option type introduced between the old and new version (use the GitHub compare / changelog, not only commit titles):

New validator (check API)
  • src/chain/validators.ts: under // validator's validators, add the new method signature in alphabetical order with the rest. Follow existing JSDoc style for adjacent methods.
  • src/chain/validators-impl.ts: under // Standard validators, add the implementation in alphabetical order, delegating with addStandardValidation(validator.<name>, ...) the same way sibling methods do. If upstream uses custom logic (see e.g. isAlpha, toArray-style), match the existing pattern in that file.
Show full SKILL.md (180 more words)Show less
New sanitizer
  • src/chain/sanitizers.ts: under // validator's sanitizers, add the method in alphabetical order.
  • src/chain/sanitizers-impl.ts: under // Standard sanitizers, add the implementation in alphabetical order (addStandardSanitization vs customSanitizer as appropriate).
New options / types
  • src/options.ts: add or extend types only when the new value is:
    • enum-like (e.g. a new locale, a new UUID version constant), or
    • an object (e.g. { min, max }, or other structured options).
  • Skip options.ts for parameters that are only a plain string or number with no new shared option shape—use inline types on the chain method if needed, consistent with nearby code.
Everything else
  • Upstream internal or non–type-surface changes that do not add or change validator/sanitizer signatures need no express-validator edits beyond the version bump and declaration sync (if any).

3. Declarations

  • Update declarations/validator.d.ts: new export function entries must stay in alphabetical order and match the installed validator call signatures. Reuse import('../src/options').<Type> for option types the same way existing declarations do.

4. Verify

From the repo root:

bash
npm test
npm run lint
npm run docs:regenerate-api

Fix any failures before finishing.

Quick reference — section markers

FileSection comment
src/chain/validators.ts// validator's validators
src/chain/validators-impl.ts// Standard validators
src/chain/sanitizers.ts// validator's sanitizers
src/chain/sanitizers-impl.ts// Standard sanitizers

© express-validator, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/upgrade-validator of express-validator/express-validator.

Open the folder on GitHubat commit 48d44de

Compare with similar skills

Validator Dependency Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validator Dependency Upgrade compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validator Dependency Upgrade this skillexpress-validator/express-validator6.2k—~1.2kAutomated safety check: PassMIT
GitVersion .NET DevelopmentGitTools/GitVersion3.1k—~1.7kAutomated safety check: PassMIT
Claude Code Version Checkykdojo/claude-code-tips10k—~1.8kAutomated safety check: PassCustom licence
Setup Pre Commitfossasia/eventyay-interpretation1.6k12 repos~565Automated safety check: PassApache-2.0
Bun Runtimespinspire/pocketbase-sveltekit-starter5115 repos~653Automated safety check: NotesMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT

Similar skills

  • GitVersion .NET Development

    GitTools/GitVersion

    Gives repository-specific .NET guidance for GitVersion: build and test commands, central package management, project layout and coding conventions.

    3.1k GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Claude Code Version Check

    ykdojo/claude-code-tips

    Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.

    10k GitHub stars~1.8k tokensUpdated 12 days ago
    DevelopmentAuto-check passed
  • Setup Pre Commit

    fossasia/eventyay-interpretation

    Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo.

    1.6k GitHub starsUsed in 12 repos~565 tokens
    DevelopmentAuto-check passed
  • Bun Runtime

    spinspire/pocketbase-sveltekit-starter

    Bun as runtime, package manager, bundler, and test runner. An agent skill from spinspire/pocketbase-sveltekit-starter.

    511 GitHub starsUsed in 5 repos~653 tokens
    DevelopmentAuto-check: notes
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.

    2k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check: warnings

Works with

Categories

Questions about Validator Dependency Upgrade

What does Validator Dependency Upgrade do?

Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release. express-validator holds the validator dependency to patch-only semver so an unexpected upstream minor release cannot slip in, which makes each bump a deliberate maintainer task.json, runs npm install validator@latest, and if npm rewrites the range with a caret, changes it back to a tilde range to match the project's convention.

When should I use Validator Dependency Upgrade?

Validator Dependency Upgrade fits situations like: bumping validator to a newer release inside the express-validator repository; adding chain methods for validators or sanitizers that are new in validator.js; keeping declarations/validator.d.ts aligned with the upstream package.

How do I install Validator Dependency Upgrade in Claude Code?

Run `npx skills add express-validator/express-validator --skill upgrade-validator -a claude-code`. Or copy the skill folder (.agents/skills/upgrade-validator in express-validator/express-validator) into .claude/skills/upgrade-validator in your project. Claude Code loads it when a task matches its description.

How do I install Validator Dependency Upgrade in Codex?

Run `npx skills add express-validator/express-validator --skill upgrade-validator -a codex`. Or copy the skill folder (.agents/skills/upgrade-validator in express-validator/express-validator) into .agents/skills/upgrade-validator in your project. Codex loads it when a task matches its description.

Can I use Validator Dependency Upgrade in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add express-validator/express-validator --skill upgrade-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-validator, .gemini/skills/upgrade-validator, .github/skills/upgrade-validator and .opencode/skills/upgrade-validator in your project.

What does Validator Dependency Upgrade need to run?

Going by SKILL.md and its folder, Validator Dependency Upgrade needs the command-line tools its instructions call (npm). Our summary lists: npm; A checkout of the express-validator repository.

Does Validator Dependency Upgrade access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Validator Dependency Upgrade safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Validator Dependency Upgrade use?

Validator Dependency Upgrade is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validator Dependency Upgrade use?

About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validator Dependency Upgrade?

Skills that share tags, products or a category with Validator Dependency Upgrade: GitVersion .NET Development (GitTools/GitVersion, 3.1k stars), Claude Code Version Check (ykdojo/claude-code-tips, 10k stars), Setup Pre Commit (fossasia/eventyay-interpretation, 1.6k stars) and Bun Runtime (spinspire/pocketbase-sveltekit-starter, 511 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validator Dependency Upgrade?

express-validator (a GitHub organization) maintains it in express-validator/express-validator, which has 6,233 GitHub stars. The repository was last updated on October 3, 2026.

Source: express-validator/express-validator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.