Agent skill

Update Deps

by stella in stella/stella

Inventory, assess, update, and validate third-party dependencies across Bun, Python/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk.

Apache-2.0Auto-check passedDevOps & Cloud

Install Update Deps

skills CLI
$ npx skills add stella/stella --skill update-deps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install stella/stella update-deps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/stella/stella.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/update-deps .claude/skills/update-deps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-deps
GitHub stars
258
Token cost
~2.7k tokens
SKILL.md length
1,289 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Inventory, assess, update, and validate third-party dependencies across Bun, Python/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk.

  • Works in 5 steps: Resolve Scope and Sources of Truth → Inventory the Full Requested Surface → Assess Upgrade and Supply-Chain Risk → …
  • Tasks that involve Supply chain security
  • SKILL.md covers 1. Resolve Scope and Sources…, 2. Inventory the Full…, 3. Assess Upgrade and… and 4. Apply Deliberate Updates, plus 1 more section
  • Calls bun, cargo and uv

What it does

Update Deps is an agent skill from stella/stella. Inventory, assess, update, and validate third-party dependencies across Bun, Python/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Supply chain security, CI/CD and Containers. It works with Docker, GitHub Actions and Python. The repository describes itself as: Open-source legal workspace. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve CI/CD
  • Tasks that involve Containers

Example prompts

  • “/update-deps”

Requirements

  • Python 3
  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Resolve Scope and Sources of Truth
  2. Inventory the Full Requested Surface
  3. Assess Upgrade and Supply-Chain Risk
  4. Apply Deliberate Updates
  5. Validate and Report

What it can do on your machine

Read from SKILL.md and the folder at commit 269655d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • cargo
    • uv
    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Deps loads about 2.7k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 1,289 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from stella/stella at commit 269655d, republished under its Apache-2.0 licence (© stella). 1,289 words, ~2,725 tokens.

Download SKILL.mdSave it as .claude/skills/update-deps/SKILL.md (or your agent's skills folder).
name
update-deps
description
Inventory, assess, update, and validate third-party dependencies across Bun, Python/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk.
<!-- This local skill replaces the shared update-deps skill (.ai/shared/skills/update-deps/SKILL.md) to add the anonymizer rules below. When the shared skill changes, reconcile this file with it and record the new base in .ai/local-skills/shared-bases.sha256; scripts/check-local-skill-overrides.sh fails until then. -->

Update Dependencies

Review or update the dependency scope requested by the user. Discover the repository's actual manifests and source-of-truth files before running ecosystem commands; do not assume they live at the root.

1. Resolve Scope and Sources of Truth

Inspect repository instructions, workspace manifests, lockfiles, dependency catalogs or resolutions, automated update configuration, and open dependency PRs when relevant. Common sources include:

  • package.json, workspace manifests, bun.lock, and bunfig.toml
  • every relevant pyproject.toml, uv.lock, and Python constraints file
  • every relevant Cargo.toml and its Cargo.lock
  • Dockerfile* and Compose YAML
  • .github/workflows/* and dependency-update configuration

Default to an inventory and recommendation unless the user asks to apply updates. When applying a broad sweep, split it into coherent, independently validated batches. Give every major and heavy minor its own validated batch and commit. A heavy minor is a minor whose official release notes require migration or whose application requires source, configuration, or schema changes beyond dependency manifests and lockfiles.

"Separate" means its own batch and commit, not its own pull request and not omitted. An applied sweep covers every applicable update within the requested scope and each dependency's intended registry channel. Keep stable dependencies on stable releases. Include prerelease updates only within an explicitly selected prerelease channel. The only reason to leave a version behind is a mechanical block: a release still inside the repository's release-age quarantine, a peer or engine constraint that cannot be satisfied, or an upstream break with no migration path. Report each block with its reason. Upgrade size, review burden, and "risky major" are not blocks.

For every major and heavy minor, read the official release notes for capabilities worth adopting, not only for breakage. Report the relevant migration details and capabilities adopted or identified with the version moves.

Anonymizer Packages

@stll/anonymize, @stll/anonymize-wasm, and @stll/anonymize-data decide what leaves the workspace in anonymized chat, so any version move of them, patch included and whether alone or in a sweep, follows these rules:

  1. Measure before and after. Before changing the version, with the current version installed, record the per-class corpus tallies:

    bash
    bun apps/api/scripts/name-matching-corpus.ts --failures > /tmp/corpus-before.txt

    Run it again after the update and put both tallies, or their difference, in the pull request.

  2. The name-matching gates pass. From apps/api, run the corpus gate and the real-anonymizer suites against the new version:

    bash
    bun run test src/mcp/name-matching-corpus.test.ts \
      src/mcp/anonymization.test.ts \
      src/handlers/chat/stored-parts-send-mode.integration.test.ts \
      src/handlers/chat/provider-request-schemas.integration.test.ts \
      src/handlers/chat/provider-request-roles.integration.test.ts
    bun run test:property src/mcp/anonymization.property.test.ts

    and, from packages/anonymize-chat, bun run test:property. These run the native binding; the anonymize-chat property suite uses a stand-in runtime.

  3. The WASM build is exercised for real. When @stll/anonymize-wasm moves, run bun --filter @stll/web test:e2e:landing: it drives the shipped WASM bundle in a browser and fails when the engine does not boot or detect. No automated test yet runs the chat worker's deny-list matching on the real WASM build, so also check it by hand on a local stack (bun run agent:up): add short, inflected, and diacritic names to a workspace deny list, send an anonymized chat that uses them, confirm each is replaced in the request the provider receives, and state the result in the pull request.

  4. Bounds only tighten. Never lower a recall floor or raise a false-positive ceiling in name-matching-corpus.test.ts (or relax a property test) to make the update pass, unless the pull request states the reason, the classes and cases affected, and the before and after tallies, and that justification is reviewed and approved before merge. Raise a floor or lower a ceiling when the new version does better.

2. Inventory the Full Requested Surface

Run Bun inventory from the workspace root:

bash
bun outdated --filter="*"

For each relevant Rust manifest, inspect the full dependency graph:

bash
cargo outdated --manifest-path <path/to/Cargo.toml>

If cargo-outdated is unavailable, preview compatible lockfile updates with:

bash
cargo update --manifest-path <path/to/Cargo.toml> --dry-run

This dry run is an incomplete inventory: it cannot surface releases outside the manifest's current version requirements. Supplement it with registry-aware cargo info or cargo search checks for every direct dependency in scope, and report the limitation. Do not default to --root-deps-only when cargo-outdated is available: transitive changes can carry the material risk.

For each uv-managed Python project, inspect direct and transitive packages:

bash
uv tree --project <path> --locked --outdated

Also compare every direct dependency's declared constraint with authoritative PyPI metadata. uv tree --outdated can hide a newer release when the current constraint excludes it, so it is not a complete major-version inventory by itself. Keep accelerator packages and their container runtime in one compatibility batch: verify the Python wheel's CUDA/ROCm requirements against the selected base image and exercise a native-library import or linkage smoke test.

Inventory container references across Dockerfiles and Compose files:

bash
rg -n '^\s*(FROM|image:)\s+' \
  --glob 'Dockerfile*' \
  --glob '*compose*.yml' \
  --glob '*compose*.yaml' \
  --glob '!node_modules/**'

Resolve current tags and digests from authoritative registry metadata. Inspect GitHub Actions when requested or when workflow files are in scope.

Flag exact prerelease pins and non-stable channels separately. Package-manager "latest" output can miss a newer alpha, beta, rc, next, canary, or dev release on the intended channel. Query registry tags and compare the deliberate channel.

Show full SKILL.md (507 more words)Show less

3. Assess Upgrade and Supply-Chain Risk

Treat patch, minor, major, pre-1.0 minor, and prerelease moves according to their actual compatibility risk. Read official release notes, migration guides, engine or peer requirements, image notes, and package metadata. Search current usage for deprecated APIs, compatibility shims, and workarounds the release could remove.

Before adopting a fresh or high-risk release, inspect cheap signals first:

  • release age relative to repository quarantine policy
  • publisher, maintainer, repository, or homepage changes
  • missing tags or unexplained release notes
  • new lifecycle scripts, native binaries, or bundled blobs
  • image provenance, supported platforms, and digest movement

Use package tarball or image-layer inspection only when those signals are odd, the dependency is high risk, or the user requested a deeper audit. Prefer official sources and registry metadata over third-party summaries.

4. Apply Deliberate Updates

Update the real source of truth: a shared catalog or resolution before duplicating versions across workspaces. Preserve the intended prerelease channel explicitly; do not use a flag that silently replaces it with stable latest.

For Bun versions already allowed by the manifest, update only the planned packages:

bash
bun update <package>

When a shared catalog owns the version, edit that catalog and run bun install instead of creating workspace drift. Use bun update <package> --latest only when intentionally changing the declared dependency range. Resolve and preserve an intended prerelease version or channel explicitly.

For Rust, use targeted lockfile updates:

bash
cargo update --manifest-path <path/to/Cargo.toml> -p <crate>

Edit the manifest only when the declared requirement must change. Do not run bare cargo update for an ordinary batch; a full-graph update must be an explicit, reviewed choice.

For uv, update only the planned packages and review the resulting lockfile:

bash
uv lock --project <path> --upgrade-package <package>
uv sync --project <path> --frozen

Edit pyproject.toml when intentionally widening or changing a direct dependency constraint. Do not run an unscoped full Python upgrade unless the batch explicitly covers the full Python graph.

Pin GitHub Actions to commit SHAs and container images to immutable digests when that is repository policy. Review every manifest and lockfile delta for unexpected transitive additions, replacements, features, scripts, or platform changes.

Prefer removal over passive growth: delete obsolete shims, polyfills, or duplicate packages when the upgrade makes them unnecessary and the validation surface remains focused.

5. Validate and Report

Run the smallest affected checks first, then the repository's canonical verification for the touched surface. Use each Rust command with its actual manifest path, for example:

bash
cargo check --manifest-path <path/to/Cargo.toml>
cargo test --manifest-path <path/to/Cargo.toml>

Use each Python command against its actual project and locked environment, for example:

bash
uv lock --project <path> --check
uv run --project <path> --locked <lint-or-test-command>

For native or GPU packages, also build the production image and run the repository's import/linkage smoke test so a resolver-green but ABI-incompatible update cannot land.

Run the repository's dependency or security audit command when it defines one, for example bun run security:audit, and report its result. Do not substitute a generic command for repository policy when no such audit is configured.

Verify generated artifacts when a dependency affects them. If applying multiple batches, commit each only after its validation passes so rollback remains clear.

Report the full inventory, current and target versions, risk classification, official migration evidence, concrete adoption opportunities, supply-chain assessment, applied batches, checks run, and deferred or blocked work.

© stella, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/update-deps of stella/stella.

Open the folder on GitHubat commit 269655d

Compare with similar skills

Update Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Deps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Deps this skillstella/stella258—~2.7kAutomated safety check: PassApache-2.0
DDNS Build and Release MaintenanceNewFuture/DDNS4.7k—~444Automated safety check: PassMIT
Code PatternsAedelon/claude-code-blueprint120—~1.2kAutomated safety check: PassCustom licence
CI/CD Pipeline Principlesirahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT
Devops Deploysickn33/agentic-awesome-skills47k2 repos~1.9kAutomated safety check: PassMIT
Uvharperreed/dotfiles334—~1.1kAutomated safety check: PassNone

Similar skills

  • Maintains the DDNS project's GitHub Actions, Docker and Nuitka builds, packaging and release preparation without touching publishing credentials.

    4.7k GitHub stars~444 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Code Patterns

    Aedelon/claude-code-blueprint

    Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    157 GitHub stars~2.7k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Devops Deploy

    sickn33/agentic-awesome-skills

    DevOps e deploy de aplicacoes — Docker, CI/CD com GitHub Actions, AWS Lambda, SAM, Terraform, infraestrutura como codigo e monitoramento.

    47k GitHub starsUsed in 2 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Uv

    harperreed/dotfiles

    uv workflows for Python — dependencies, virtualenvs, PEP 723 scripts, Python version management, CI, and Docker.

    334 GitHub stars~1.1k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed

More from stella/stella

All 24 skills in this repo
  • Plan

    stella/stella

    Create a concise, evidence-backed implementation plan in the repository planning area when the user explicitly asks for a plan.

    258 GitHub stars~917 tokensUpdated today
    Auto-check passed
  • Answer From Sources

    stella/stella

    Answers data-protection (GDPR) questions grounded in the regulation and supervisory guidance, with a citation for every claim.

    258 GitHub stars~735 tokensUpdated today
    Auto-check passed
  • Check Against Rules

    stella/stella

    Reviews a non-disclosure agreement against the firm's NDA checklist and reports findings with citations.

    258 GitHub stars~856 tokensUpdated today
    Auto-check passed
  • Intake To Draft

    stella/stella

    Collects the facts of an unpaid invoice, then drafts a payment demand letter.

    258 GitHub stars~537 tokensUpdated today
    Auto-check passed
  • Conventions Perf

    stella/stella

    Apply when a performance-guard check (network baseline, bundle baseline, DB query count, loader-prefetch lint, RC bailouts) fails or when touching a hot route/endpoint.

    258 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Apply when writing or reviewing React effects in apps/web. An agent skill from stella/stella.

    258 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Update Deps

What does Update Deps do?

Inventory, assess, update, and validate third-party dependencies across Bun, Python/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk. Update Deps is an agent skill from stella/stella. Inventory, assess, update, and validate third-party dependencies across Bun, Python/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk.

When should I use Update Deps?

Update Deps fits situations like: tasks that involve Supply chain security; tasks that involve CI/CD; tasks that involve Containers.

How do I install Update Deps in Claude Code?

Run `npx skills add stella/stella --skill update-deps -a claude-code`. Or copy the skill folder (.agents/skills/update-deps in stella/stella) into .claude/skills/update-deps in your project. Claude Code loads it when a task matches its description.

How do I install Update Deps in Codex?

Run `npx skills add stella/stella --skill update-deps -a codex`. Or copy the skill folder (.agents/skills/update-deps in stella/stella) into .agents/skills/update-deps in your project. Codex loads it when a task matches its description.

Can I use Update Deps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add stella/stella --skill update-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-deps, .gemini/skills/update-deps, .github/skills/update-deps and .opencode/skills/update-deps in your project.

What does Update Deps need to run?

Going by SKILL.md and its folder, Update Deps needs the command-line tools its instructions call (bun, cargo, uv and rg). Our summary lists: Python 3; Docker.

Does Update Deps access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update Deps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Deps use?

Update Deps is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Deps use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Deps?

Skills that share tags, products or a category with Update Deps: DDNS Build and Release Maintenance (NewFuture/DDNS, 4.7k stars), Code Patterns (Aedelon/claude-code-blueprint, 120 stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars) and Devops Deploy (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Deps?

stella (a GitHub organization) maintains it in stella/stella, which has 258 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 8, 2026.

Source: stella/stella on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.