Agent skill

Bump Dependencies

by jhb-software in jhb-software/payload-plugins

Run the bundled bump-dependencies.sh to bump plugin dependencies, then walk every non-patch version change to surface breaking changes and apply any plugin-side updates needed.

No licenceAuto-check passedDevelopment

Install Bump Dependencies

skills CLI
$ npx skills add jhb-software/payload-plugins --skill bump-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jhb-software/payload-plugins bump-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jhb-software/payload-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/bump-dependencies .claude/skills/bump-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bump-dependencies
GitHub stars
104
Token cost
~3.2k tokens
SKILL.md length
1,610 words
Files
3
Skills in repo
3
Repo updated
First seen
Licence
None found

At a glance

Run the bundled bump-dependencies.sh to bump plugin dependencies, then walk every non-patch version change to surface breaking changes and apply any plugin-side updates needed.

  • Works in 8 steps: Confirm scope. Default is all plugins.… → Run the script. It lives next to this… → List non-patch bumps. From the resulting… → …
  • The user says bump dependencies
  • SKILL.md covers Steps, Reconcile pnpm-workspace.yaml…, Audit for vulnerabilities and… and Heuristics for what to read…, plus 1 more section
  • Runs Shell scripts from its folder; calls pnpm, git and gh

What it does

Bump Dependencies is an agent skill from jhb-software/payload-plugins. Run the bundled bump-dependencies.sh to bump plugin dependencies, then walk every non-patch version change to surface breaking changes and apply any plugin-side updates needed. Also audits every workspace for security advisories (audit-dependencies.sh) and fixes them via override floors or direct-dependency pins. Use when the user says "bump dependencies", "upgrade dependencies", "update dependencies", "audit dependencies", "check for vulnerabilities", or wants to refresh a single plugin's dependencies.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `audit-dependencies.sh` and `bump-dependencies.sh`).

It sits in Development. It works with Payload CMS and GitHub. The repository describes itself as: A collection of powerful plugins designed to enhance Payload CMS.

When your agent uses it

  • The user says bump dependencies
  • Upgrade dependencies
  • Update dependencies
  • Audit dependencies

Example prompts

  • “bump dependencies”
  • “upgrade dependencies”
  • “update dependencies”
  • “/bump-dependencies”

Requirements

  • A Bash shell

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Confirm scope. Default is all plugins. If the user names one (bump dependencies for chat-agent), pass it as the script arg. Refuse to run…
  2. Run the script. It lives next to this skill so it travels with it. Run it from the repo root
  3. List non-patch bumps. From the resulting diff, extract every dependency whose new version is a minor or major jump. Patch bumps (1.2.3 →…
  4. For each non-patch bump, read the upstream changelog. Pick the cheapest source that covers all intermediate versions, not just the new one
  5. Grep the plugin for affected APIs. For each breaking change the changelog calls out, grep the plugin source (/src/) and the dev app…
  6. Apply needed plugin-side updates. For each real hit from step 5, edit the plugin source to match the new API. Re-run the plugin's checks
  7. Update the affected plugin's CHANGELOG.md only if the upgrade required user-visible plugin changes (a peer-dependency range bumped to a…
  8. Report back, in this shape

What it can do on your machine

Read from SKILL.md and the folder at commit 43204de. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • pnpm
    • git
    • gh
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, git, gh and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bump Dependencies loads about 3.2k tokens when it runs. Until then it costs about 132 tokens; SKILL.md has 1,610 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~132
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,610 words (~3,178 tokens).

“Goal: bump the dependencies via the bundled script, then for every non-patch jump confirm the plugin still works against the new version — read the upstream changelog, grep the plugin for affected APIs, and apply fixes.”

— opening of SKILL.md by jhb-software
name
bump-dependencies

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files in .claude/skills/bump-dependencies of jhb-software/payload-plugins.

  • SKILL.md
  • audit-dependencies.sh
  • bump-dependencies.sh

Open the folder on GitHubat commit 43204de

Compare with similar skills

Bump Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bump Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bump Dependencies this skilljhb-software/payload-plugins104—~3.2kAutomated safety check: PassNone
Triage CI Flakepayloadcms/payload45k—~4.4kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Setup Matt Pocock Skillsbestofjs/bestofjs3.1k20 repos~1.7kAutomated safety check: PassMIT

Similar skills

  • Triage CI Flake

    payloadcms/payload

    A skill your agent uses when CI tests fail on main branch after PR merge, when investigating flaky test failures, or when user provides a PR URL/number to aggregate all failing tests

    45k GitHub stars~4.4k tokensUpdated today
    Testing & QAAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Setup Matt Pocock Skills

    bestofjs/bestofjs

    Configure this repo for the engineering skills — set up its issue tracker, triage label vocabulary, and domain doc layout.

    3.1k GitHub starsUsed in 20 repos~1.7k tokens
    DevelopmentAuto-check passed
  • Official

    A skill your agent uses when a user says "summarise ecosystem results", "summarize this ty ecosystem report", "what changed in this ecosystem run?", or asks to summarise or summarize ty ecosystem…

    50k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed

More from jhb-software/payload-plugins

  • Verify PR

    jhb-software/payload-plugins

    Check out a GitHub PR, identify the plugin it touches, start that plugin's dev app, and tell the user the exact page + steps to exercise the change in the admin panel.

    104 GitHub stars~735 tokensUpdated yesterday
    Auto-check passed
  • Fix Payload Duplicate Deps

    jhb-software/payload-plugins

    Fix Payload admin crashes from duplicate @payloadcms/ui/payload/react in the dep graph.

    104 GitHub stars~498 tokensUpdated yesterday
    Auto-check: warnings

Categories

Questions about Bump Dependencies

What does Bump Dependencies do?

Run the bundled bump-dependencies.sh to bump plugin dependencies, then walk every non-patch version change to surface breaking changes and apply any plugin-side updates needed. Bump Dependencies is an agent skill from jhb-software/payload-plugins.sh to bump plugin dependencies, then walk every non-patch version change to surface breaking changes and apply any plugin-side updates needed.

When should I use Bump Dependencies?

Bump Dependencies fits situations like: the user says bump dependencies; upgrade dependencies; update dependencies; audit dependencies.

How do I install Bump Dependencies in Claude Code?

Run `npx skills add jhb-software/payload-plugins --skill bump-dependencies -a claude-code`. Or copy the skill folder (.claude/skills/bump-dependencies in jhb-software/payload-plugins) into .claude/skills/bump-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Bump Dependencies in Codex?

Run `npx skills add jhb-software/payload-plugins --skill bump-dependencies -a codex`. Or copy the skill folder (.claude/skills/bump-dependencies in jhb-software/payload-plugins) into .agents/skills/bump-dependencies in your project. Codex loads it when a task matches its description.

Can I use Bump Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jhb-software/payload-plugins --skill bump-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bump-dependencies, .gemini/skills/bump-dependencies, .github/skills/bump-dependencies and .opencode/skills/bump-dependencies in your project.

What does Bump Dependencies need to run?

Going by SKILL.md and its folder, Bump Dependencies needs a shell for the scripts in its folder and the command-line tools its instructions call (pnpm, git, gh and npm). Our summary lists: A Bash shell.

Does Bump Dependencies access the network?

SKILL.md contains no URLs. Its commands use git, gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Bump Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bump Dependencies use?

No licence was found for Bump Dependencies or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Bump Dependencies use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bump Dependencies?

Skills that share tags, products or a category with Bump Dependencies: Triage CI Flake (payloadcms/payload, 45k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Greploop (onyx-dot-app/onyx, 32k stars) and Check PR (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bump Dependencies?

jhb-software (a GitHub organization) maintains it in jhb-software/payload-plugins, which has 104 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 6, 2026.

Source: jhb-software/payload-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.