Validator Dependency Upgrade
express-validator/express-validator
Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.
Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…
$ npx skills add logseq/logseq --skill logseq-dependency-upgrade -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install logseq/logseq logseq-dependency-upgrade --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/logseq-dependency-upgrade .claude/skills/logseq-dependency-upgrade && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "logseq-dependency-upgrade" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/logseq-dependency-upgrade into .claude/skills/logseq-dependency-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "logseq-dependency-upgrade", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/logseq/logseq/tree/master/.agents/skills/logseq-dependency-upgradeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add logseq/logseq --skill logseq-dependency-upgrade -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install logseq/logseq logseq-dependency-upgrade --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/logseq-dependency-upgrade .agents/skills/logseq-dependency-upgrade && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "logseq-dependency-upgrade" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/logseq-dependency-upgrade into .agents/skills/logseq-dependency-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "logseq-dependency-upgrade", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add logseq/logseq --skill logseq-dependency-upgrade -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install logseq/logseq logseq-dependency-upgrade --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/logseq-dependency-upgrade .cursor/skills/logseq-dependency-upgrade && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "logseq-dependency-upgrade" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/logseq-dependency-upgrade into .cursor/skills/logseq-dependency-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "logseq-dependency-upgrade", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/logseq/logseq.git --path .agents/skills/logseq-dependency-upgrade--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add logseq/logseq --skill logseq-dependency-upgrade -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install logseq/logseq logseq-dependency-upgrade --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/logseq-dependency-upgrade .gemini/skills/logseq-dependency-upgrade && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "logseq-dependency-upgrade" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/logseq-dependency-upgrade into .gemini/skills/logseq-dependency-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "logseq-dependency-upgrade", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install logseq/logseq logseq-dependency-upgradeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add logseq/logseq --skill logseq-dependency-upgrade -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/logseq-dependency-upgrade .github/skills/logseq-dependency-upgrade && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "logseq-dependency-upgrade" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/logseq-dependency-upgrade into .github/skills/logseq-dependency-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "logseq-dependency-upgrade", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add logseq/logseq --skill logseq-dependency-upgrade -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install logseq/logseq logseq-dependency-upgrade --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/logseq-dependency-upgrade .opencode/skills/logseq-dependency-upgrade && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "logseq-dependency-upgrade" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/logseq-dependency-upgrade into .opencode/skills/logseq-dependency-upgrade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "logseq-dependency-upgrade", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
logseq-dependency-upgradeAudit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…
Logseq Dependency Upgrade is an agent skill from logseq/logseq. Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions, cross-root consistency, lockfile resolution, deprecation, staleness, and OSV vulnerabilities, then generating a batch-ordered upgrade plan and compact JSON artifact.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.
It sits in Knowledge Management, covering Dependency management. It works with npm. The repository describes itself as: A privacy-first, open-source platform for knowledge management and collaboration. Download link: http://github.com/logseq/logseq/releases. roadmap: https://logseq.io/p/NX4mcggEV. The licence is AGPL-3.0.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 22a29b3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Logseq Dependency Upgrade loads about 1.1k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 471 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from logseq/logseq at commit 22a29b3, republished under its AGPL-3.0 licence (© logseq). 471 words, ~1,066 tokens.
.claude/skills/logseq-dependency-upgrade/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this skill when the task is to audit dependencies, build an upgrade plan, or refresh dependency-upgrade facts for this repository.
node .agents/skills/logseq-dependency-upgrade/scripts/audit_logseq_dependencies.mjs \
--output-json <json-output-path> \
--output-md <markdown-output-path> \
[--stale-months <months>] \
[--max-update-interval <months>] \
[--include-prerelease]--stale-months — number of months since last publish to flag a package as stale (default: 36).--max-update-interval — maximum number of months between the current version's publish date and the latest version's publish date. If the interval is within this threshold, the package is NOT considered outdated and is excluded from upgrade batches (default: 6).--include-prerelease — boolean flag (no value). When present, the Risk column annotates any newer upstream pre-release version (SNAPSHOT / RC / alpha / beta / nightly / canary etc.). The target version is always the latest stable release regardless of this flag. When absent (default), pre-release versions are neither fetched nor shown.Read the generated Markdown report — it is the primary planning document, structured for batch-wise execution.
To execute an upgrade batch:
CAUTION: Verify dependency usage before updating; remove unused packages instead of upgrading. For any dependency crossing a major version boundary, perform a rigorous review for breaking changes.
package.json (dependencies + devDependencies).deps.edn and nbb.edn (:deps + :aliases extra-deps / replace-deps — covers clj-kondo, test deps, etc.).bb.edn (:deps + :pods).local/root deps (e.g. logseq/db, logseq/common) are excluded.Target versions preserve the original specifier prefix. If current is ^1.0.0 and latest is 1.5.0, target is ^1.5.0. If current is 1.0.0 (fixed), target is 1.5.0.
For npm packages with a range specifier (e.g. ^), the script checks pnpm-lock.yaml to see if the resolved version already matches latest. These packages are flagged as already resolved — they need only a manifest/range update, not a lockfile refresh/install, and carry zero upgrade risk.
The script writes:
batches[] array for machine consumption.deprecated comes from upstream package metadata.vulnerabilities come from OSV batch queries.stale / low-maintenance is based on upstream publish dates.© logseq, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in .agents/skills/logseq-dependency-upgrade of logseq/logseq.
Open the folder on GitHubat commit 22a29b3
Logseq Dependency Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Logseq Dependency Upgrade this skilllogseq/logseq | 45k | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | |
| Validator Dependency Upgradeexpress-validator/express-validator | 6.2k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Claude Code Version Checkykdojo/claude-code-tips | 10k | — | ~1.8k | Automated safety check: Pass | Custom licence | |
| Agent SDK Version Bumppreset-io/agor | 1.4k | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| Bun Runtimespinspire/pocketbase-sveltekit-starter | 511 | 5 repos | ~653 | Automated safety check: Notes | MIT | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT |
express-validator/express-validator
Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.
ykdojo/claude-code-tips
Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.
preset-io/agor
Upgrades a pinned agent SDK in the agor project, such as the Claude, Codex or Gemini CLI one, and plans the release that carries it to packaged installs.
spinspire/pocketbase-sveltekit-starter
Bun as runtime, package manager, bundler, and test runner. An agent skill from spinspire/pocketbase-sveltekit-starter.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
aubepkg/aube
Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.
logseq/logseq
Compare two revisions of the Logseq logseq-review-workflow skill by running the same review prompt against isolated before and after skill snapshots, collecting both outputs, and producing a…
logseq/logseq
Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.
logseq/logseq
Build, debug, or review Logseq plugins with the @logseq/libs SDK (TypeScript/JavaScript, iframe/shadow sandboxed).
logseq/logseq
Operate the current Logseq command-line interface to inspect or modify graphs, pages, blocks, tasks, tags, and properties; run Datascript queries; show page/block trees; manage graphs; and manage…
logseq/logseq
Logseq i18n workflow for adding, renaming, reviewing, or editing translation keys and user-facing strings.
logseq/logseq
Answer user questions about the Logseq repository by researching source code, docs, tests, runtime behavior, and local tools.
Works with
Categories
Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…. Logseq Dependency Upgrade is an agent skill from logseq/logseq.edn manifest, checking latest upstream versions, cross-root consistency, lockfile resolution, deprecation, staleness, and OSV vulnerabilities, then generating a batch-ordered upgrade plan and compact JSON artifact.
Logseq Dependency Upgrade fits situations like: tasks that involve Dependency management.
Run `npx skills add logseq/logseq --skill logseq-dependency-upgrade -a claude-code`. Or copy the skill folder (.agents/skills/logseq-dependency-upgrade in logseq/logseq) into .claude/skills/logseq-dependency-upgrade in your project. Claude Code loads it when a task matches its description.
Run `npx skills add logseq/logseq --skill logseq-dependency-upgrade -a codex`. Or copy the skill folder (.agents/skills/logseq-dependency-upgrade in logseq/logseq) into .agents/skills/logseq-dependency-upgrade in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add logseq/logseq --skill logseq-dependency-upgrade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/logseq-dependency-upgrade, .gemini/skills/logseq-dependency-upgrade, .github/skills/logseq-dependency-upgrade and .opencode/skills/logseq-dependency-upgrade in your project.
Going by SKILL.md and its folder, Logseq Dependency Upgrade needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Logseq Dependency Upgrade is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Logseq Dependency Upgrade: Validator Dependency Upgrade (express-validator/express-validator, 6.2k stars), Claude Code Version Check (ykdojo/claude-code-tips, 10k stars), Agent SDK Version Bump (preset-io/agor, 1.4k stars) and Bun Runtime (spinspire/pocketbase-sveltekit-starter, 511 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
logseq (a GitHub organization) maintains it in logseq/logseq, which has 45,158 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.
Source: logseq/logseq on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.