Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo).

MITAuto-check passedDevelopment

Install Deps Update

skills CLI
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill deps-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install oliver-kriska/claude-elixir-phoenix deps-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/elixir-phoenix/skills/deps-update .claude/skills/deps-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deps-update
GitHub stars
565
Token cost
~1.4k tokens
SKILL.md length
525 words
Files
5 (incl. references)
Skills in repo
109
Repo updated
First seen
Licence
MIT

At a glance

Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo).

  • Works in 8 steps: Discover → Inventory → Scope (AskUserQuestion) → …
  • Upgrade/bump Elixir dependencies
  • SKILL.md covers Usage, Iron Laws, Workflow and Integration, plus 1 more section
  • Calls git, gh and npm; reaches diff.hex.pm

What it does

Deps Update is an agent skill from oliver-kriska/claude-elixir-phoenix. Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo). Use to upgrade/bump Elixir dependencies or when versions fall behind. NOT for deps.get failures (/phx:investigate).

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/changelog-sources.md`, `references/coupled-groups.md` and `references/pr-strategy.md`).

It sits in Development, covering Changelog and release notes and LLM observability. It works with Elixir. The repository describes itself as: Claude Code plugin for Elixir/Phoenix/LiveView — 26 specialist agents, Iron Laws enforcement, and Tidewave MCP integration. Plan features with parallel research agents, execute… The licence is MIT.

When your agent uses it

  • Upgrade/bump Elixir dependencies
  • Versions fall behind

Example prompts

  • “/deps-update”

Requirements

  • Node.js

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Discover
  2. Inventory
  3. Scope (AskUserQuestion)
  4. Per-Package Update Loop
  5. Verify
  6. Breaking-Change Fixes
  7. Security Handoff
  8. Group, Commit, PR

What it can do on your machine

Read from SKILL.md and the folder at commit 9767a82. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • diff.hex.pm

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deps Update loads about 1.4k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 525 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from oliver-kriska/claude-elixir-phoenix at commit 9767a82, republished under its MIT licence (© oliver-kriska). 525 words, ~1,350 tokens.

Download SKILL.mdSave it as .claude/skills/deps-update/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
deps-update
description
Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo). Use to upgrade/bump Elixir dependencies or when versions fall behind. NOT for deps.get failures (/phx:investigate).
effort
high
argument-hint
[--scope patch|minor|major|all] [--pkg <name>...] [--pr-per major|area|none] [--dry-run]

Dependency Update (Freshness)

Inventory → update → fix breaks → grouped PRs. This is the only MUTATING deps skill: it edits mix.exs, mix.lock, and source. Security scanning stays in /phx:deps-audit; the vet ledger stays in /phx:deps-vet.

Usage

/phx:deps-update                       # inventory + interactive scope pick
/phx:deps-update --scope patch         # bundle all patch bumps, one PR
/phx:deps-update --pkg phoenix_live_view   # one package (+ coupled group)
/phx:deps-update --dry-run             # inventory only, no changes

Iron Laws

  1. NEVER cross a major version without an explicit mix.exs edit — mix deps.update stays within requirements. Edit the constraint first; add override: true only when mix hex.outdated <pkg> shows a transitive consumer blocking. One major per PR
  2. ALWAYS snapshot the changelog delta BEFORE updating — capture deps/<pkg>/CHANGELOG.md, then delta via mix hex.package diff. Never update blind
  3. NEVER claim an update is safe without verification — run /phx:verify (compile --warnings-as-errors + test). "Compiles" ≠ "works"
  4. ALWAYS move coupled packages together — Phoenix core, Ecto, Ash, Oban, telemetry families update in the SAME step/commit (see ${CLAUDE_SKILL_DIR}/references/coupled-groups.md)
  5. NEVER commit a partial bump — mix.lock + mix.exs edits + (for Phoenix-family) assets/package-lock.json in ONE commit
  6. HAND OFF security to /phx:deps-audit — run it on the lock diff before any PR; don't reimplement audit rules
  7. hex.outdated exit 1 is normal — it means "deps are outdated", not failure. Capture with || true

Workflow

Phase 0: Discover

Read mix.exs: deps list, umbrella (apps_path:), git/path deps, private orgs (organization:/repo: in tuples), Phoenix/Ash presence. Create scratch dir .claude/deps-update/{YYYY-MM-DD}/.

Phase 1: Inventory

mix hex.outdated --all || true — parse the text table (no JSON exists; see ${CLAUDE_SKILL_DIR}/references/update-mechanics.md). Classify each row patch/minor/major by semver delta; Update not possible = blocked major (mix.exs constraint). Write inventory.md to scratch. Render grouped table: Patch / Minor / Major / Blocked / Git-deps (manual). --dry-run stops here.

Phase 2: Scope (AskUserQuestion)

Present groups with counts and risk. Default recommendation: "Patches (N) — low risk, bundle into one PR". --scope/--pkg flags skip the prompt. When ≥2 members of a coupled group are outdated, force them into one step even under a narrower scope.

Show full SKILL.md (234 more words)Show less
Phase 3: Per-Package Update Loop

For each selected package, in coupled-group order:

  1. Snapshot deps/<pkg>/CHANGELOG.md → scratch/before/
  2. Update — patch/minor: mix deps.update <pkg> [coupled...]; major: edit mix.exs constraint (+ override: true if needed), then mix deps.update <pkg>
  3. git diff mix.lock → the REAL {pkg, old, new} set (hex.outdated says what could change; the lock diff says what did)
  4. Changelog delta: mix hex.package diff <pkg> <old>..<new> — keep the CHANGELOG hunk. Empty → gh api repos/{o}/{r}/releases fallback → compare-URL note (see ${CLAUDE_SKILL_DIR}/references/changelog-sources.md)
  5. Write scratch/{pkg}-{old}-{new}.md
  6. Phoenix-family in the diff + assets/package.json exists → npm install --prefix assets, stage assets/package-lock.json with the same commit
Phase 4: Verify

Run /phx:verify. On failure → Phase 5; else Phase 6.

Phase 5: Breaking-Change Fixes

Read the changelog deltas for "breaking"/"removed"/"deprecated" + the compile/test errors. Fix source (apply the sibling-file check). Re-verify.

Phase 6: Security Handoff

Run /phx:deps-audit on the working mix.lock diff (its Mode B default). BLOCK findings → surface and offer /phx:deps-vet <pkg> <ver> for accepted risks. Never skip this before a PR.

Phase 7: Group, Commit, PR

Apply the splitting strategy (${CLAUDE_SKILL_DIR}/references/pr-strategy.md): patches bundled, minors by area, majors solo, coupled groups always together. PR bodies cite the changelog excerpt, the https://diff.hex.pm/diff/<pkg>/<old>..<new> link, verification result, and the deps-audit risk band. Stage lock + mix.exs + package-lock together.

Integration

text
/phx:deps-update (mutating) → /phx:deps-audit (security, Mode B)
        │                              │ BLOCK → /phx:deps-vet (ledger)
        └→ /phx:verify (gate) → grouped commits / PRs

References

  • ${CLAUDE_SKILL_DIR}/references/update-mechanics.md — hex.outdated parsing, update vs unlock+get, majors, lock-diff
  • ${CLAUDE_SKILL_DIR}/references/changelog-sources.md — hex.package diff, gh fallbacks, private orgs
  • ${CLAUDE_SKILL_DIR}/references/coupled-groups.md — must-move-together groups + edge cases
  • ${CLAUDE_SKILL_DIR}/references/pr-strategy.md — grouping rules, area buckets, PR template, scratch layout

© oliver-kriska, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/elixir-phoenix/skills/deps-update of oliver-kriska/claude-elixir-phoenix.

  • SKILL.md
  • references/changelog-sources.md
  • references/coupled-groups.md
  • references/pr-strategy.md
  • references/update-mechanics.md

Open the folder on GitHubat commit 9767a82

Compare with similar skills

Deps Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deps Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deps Update this skilloliver-kriska/claude-elixir-phoenix565—~1.4kAutomated safety check: PassMIT
Elixirstreamband/hydra-srt147—~804Automated safety check: PassApache-2.0
Change CleanupSimon-Initiative/oli-torus119—~3.7kAutomated safety check: PassMIT
Elixir AntipatternsGentleman-Programming/Gentleman-Skills658—~2.1kAutomated safety check: PassMIT
Version Bumpdmkenney/xamal106—~911Automated safety check: PassMIT
Changelog Writinglangfuse/langfuse36k—~408Automated safety check: PassCustom licence

Similar skills

  • Elixir

    streamband/hydra-srt

    A skill your agent uses for Elixir/Phoenix development in this repo: implementing features, refactors, debugging, tests, Ecto changes, and production-safe fixes.

    147 GitHub stars~804 tokensUpdated 24 days ago
    DevelopmentAuto-check passed
  • Change Cleanup

    Simon-Initiative/oli-torus

    Clean up and harden code introduced by the current branch without drifting into broad refactors.

    119 GitHub stars~3.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Elixir Antipatterns

    Gentleman-Programming/Gentleman-Skills

    Core catalog of 8 critical Elixir/Phoenix anti-patterns covering error handling, separation of concerns, Ecto queries, and testing.

    658 GitHub stars~2.1k tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Version Bump

    dmkenney/xamal

    Prepare a new Xamal version locally — bump @version in mix.exs, roll the CHANGELOG.md

    106 GitHub stars~911 tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Changelog Writing

    langfuse/langfuse

    Shared workflow for writing Langfuse changelog entries after a feature is complete.

    36k GitHub stars~408 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Phoenix Release Notes

    Arize-ai/phoenix

    Create Phoenix release documentation grounded in actual code changes.

    12k GitHub stars~6.7k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from oliver-kriska/claude-elixir-phoenix

All 109 skills in this repo
  • Codex Ab

    oliver-kriska/claude-elixir-phoenix

    Run an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings, report a panel-value verdict.

    565 GitHub stars~977 tokensUpdated 5 days ago
    Auto-check passed
  • Audit

    oliver-kriska/claude-elixir-phoenix

    Project health audit and health check — architecture, performance, tests, dependencies, code quality.

    565 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with; Use when consulting past solutions…

    565 GitHub stars~528 tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with YAML frontmatter.

    565 GitHub stars~547 tokensUpdated 5 days ago
    Auto-check passed
  • Deploy

    oliver-kriska/claude-elixir-phoenix

    Elixir/Phoenix deployment patterns — Dockerfile, fly.toml, runtime.exs, mix release, rel/ overlays.

    565 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Deps Vet

    oliver-kriska/claude-elixir-phoenix

    Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner.

    565 GitHub stars~1.5k tokensUpdated 5 days ago
    Auto-check passed

Works with

Categories

Questions about Deps Update

What does Deps Update do?

Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo). Deps Update is an agent skill from oliver-kriska/claude-elixir-phoenix. Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo).

When should I use Deps Update?

Deps Update fits situations like: upgrade/bump Elixir dependencies; versions fall behind.

How do I install Deps Update in Claude Code?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill deps-update -a claude-code`. Or copy the skill folder (plugins/elixir-phoenix/skills/deps-update in oliver-kriska/claude-elixir-phoenix) into .claude/skills/deps-update in your project. Claude Code loads it when a task matches its description.

How do I install Deps Update in Codex?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill deps-update -a codex`. Or copy the skill folder (plugins/elixir-phoenix/skills/deps-update in oliver-kriska/claude-elixir-phoenix) into .agents/skills/deps-update in your project. Codex loads it when a task matches its description.

Can I use Deps Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add oliver-kriska/claude-elixir-phoenix --skill deps-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deps-update, .gemini/skills/deps-update, .github/skills/deps-update and .opencode/skills/deps-update in your project.

What does Deps Update need to run?

Going by SKILL.md and its folder, Deps Update needs the command-line tools its instructions call (git, gh and npm). Our summary lists: Node.js.

Does Deps Update access the network?

SKILL.md names 1 domain. In commands or code: diff.hex.pm; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Deps Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deps Update use?

Deps Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deps Update use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Deps Update?

Skills that share tags, products or a category with Deps Update: Elixir (streamband/hydra-srt, 147 stars), Change Cleanup (Simon-Initiative/oli-torus, 119 stars), Elixir Antipatterns (Gentleman-Programming/Gentleman-Skills, 658 stars) and Version Bump (dmkenney/xamal, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deps Update?

oliver-kriska (a GitHub user) maintains it in oliver-kriska/claude-elixir-phoenix, which has 565 GitHub stars. The repository holds 109 skills in this directory. The repository was last updated on October 5, 2026.

Source: oliver-kriska/claude-elixir-phoenix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.