Agent skill

Update Dependencies

by tobihagemann in tobihagemann/turbo

Upgrade project dependencies with breaking change research for major version updates.

MITAuto-check passedDevOps & Cloud

Install Update Dependencies

skills CLI
$ npx skills add tobihagemann/turbo --skill update-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tobihagemann/turbo update-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tobihagemann/turbo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/codex/skills/update-dependencies .claude/skills/update-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-dependencies
GitHub stars
408
Token cost
~3k tokens
SKILL.md length
1,644 words
Files
1
Skills in repo
81
Repo updated
First seen
Licence
MIT

At a glance

Upgrade project dependencies with breaking change research for major version updates.

  • Works in 7 steps: Review Dependencies → User Strategy Selection → Research Breaking Changes → …
  • The user asks to update dependencies
  • SKILL.md covers Task Tracking, Phase 1: Review Dependencies, Phase 2: User Strategy Selection and Phase 3: Research Breaking…, plus 5 more sections
  • Calls npx, cargo and rg

What it does

Update Dependencies is an agent skill from tobihagemann/turbo. Upgrade project dependencies with breaking change research for major version updates. Use when the user asks to "update dependencies", "upgrade packages", "upgrade dependencies", "update deps", "upgrade deps", "update npm deps", "update Swift packages", "cargo update", "go get updates", "bundle update", "pip upgrade", or "update GitHub Actions".

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering iOS development, CI/CD and Code migrations. It works with GitHub Actions and npm. The repository describes itself as: Reusable workflows for planning, building, reviewing, and shipping with Claude Code and Codex. The licence is MIT.

When your agent uses it

  • The user asks to update dependencies
  • Upgrade packages
  • Upgrade dependencies
  • Update npm deps

Example prompts

  • “update dependencies”
  • “upgrade packages”
  • “upgrade dependencies”
  • “/update-dependencies”

Requirements

  • Python 3
  • Node.js
  • Docker

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Review Dependencies
  2. User Strategy Selection
  3. Research Breaking Changes
  4. User Confirmation
  5. Execute Upgrades
  6. Apply Migrations
  7. Verification

What it can do on your machine

Read from SKILL.md and the folder at commit 931eda5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • cargo
    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Dependencies loads about 3k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 1,644 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tobihagemann/turbo at commit 931eda5, republished under its MIT licence (© tobihagemann). 1,644 words, ~2,959 tokens.

Download SKILL.mdSave it as .claude/skills/update-dependencies/SKILL.md (or your agent's skills folder).
name
update-dependencies
description
Upgrade project dependencies with breaking change research for major version updates. Use when the user asks to "update dependencies", "upgrade packages", "upgrade dependencies", "update deps", "upgrade deps", "update npm deps", "update Swift packages", "cargo update", "go get updates", "bundle update", "pip upgrade", or "update GitHub Actions".

Update Dependencies

Upgrade project dependencies, researching breaking changes for major version updates.

Optional filter: $ARGUMENTS (e.g., react, Alamofire, serde tokio)

Task Tracking

At the start, use update_plan to track each phase, restating any remaining steps of a parent workflow alongside them:

  1. Run $review-dependencies skill
  2. User strategy selection
  3. Research breaking changes
  4. User confirmation
  5. Execute upgrades
  6. Apply migrations
  7. Run $run-checks skill
  8. Exercise upgraded schema against the real store
  9. Report results
  10. Recommend next steps

Phase 1: Review Dependencies

Run the $review-dependencies skill to detect package managers and discover available updates. If no updates are available, stop.

Phase 2: User Strategy Selection

Before summarizing, set aside packages whose version tracks a pinned runtime or platform rather than the newest release, such as runtime type definitions and platform SDKs. Find the pin the project declares (version manager file, engines field, container base image, CI setup step) and hold any version beyond it until the pin moves.

Present a summary showing:

  • Count and list of major updates (with current → target versions)
  • Count of minor updates
  • Count of patch updates
  • Packages set aside, each with the pin that governs it

Use request_user_input for upgrade strategy (Codex request_user_input allows up to 3 options per question, so the strategies are split across two questions):

Question 1 — Header: "Approach" Options:

  • Cautious — Upgrade minor/patch first, then major one-by-one with research
  • All at once — Research all major changes, then upgrade everything together
  • Major handling — Defer the major decision (Skip-major or Interactive)

When a major upgrade would force a migration that is costly to reverse, present a Get a second opinion option in place of All at once, keeping Question 1 at three options and leaving Major handling in place so Question 2 stays reachable. It runs the $consult-claude skill for which strategy the breaking changes warrant. Then resolve the strategy with that answer in hand, re-asking when the choice stays the user's. A freeform answer asking to upgrade everything together selects the All-at-once strategy.

If the user picks Major handling, ask a follow-up:

Question 2 — Header: "Major handling" Options:

  • Skip major — Only upgrade minor and patch versions
  • Interactive — Ask for each major update individually
  • Cancel — Cancel and return to the previous step

Phase 3: Research Breaking Changes

For each package or CI action with a major version update:

Step 1: Calculate Version Gap

Identify all major versions between current and target. For example:

  • react: 17.0.2 → 19.0.0 → research v18 AND v19 breaking changes
  • Alamofire: 4.9.1 → 6.0.0 → research v5 AND v6 breaking changes
Step 2: Research Each Major Version

Search for migration documentation:

Web search: "[package-name] v[X] migration guide"
Web search: "[package-name] v[X] breaking changes"

Common sources: GitHub releases page, official docs, changelog files.

Step 3: Extract Key Breaking Changes

Identify: API changes (renamed/removed functions), configuration changes, peer/transitive dependency requirements, behavioral changes, deprecated features now removed.

Step 4: Search Codebase for Affected Code

Use rg to find usage of deprecated or changed APIs. Document which files are affected and what changes are needed.

Then check the package's installed consumers: read their declared peer or compatibility ranges and flag any range that excludes the target version. Toolchain consumers such as linters, type checkers, and build tooling can block a major even when the project's own code and configuration are clean. Carry each one into Phase 4 as a blocker.

A CI action that installs or runs the package counts as such a consumer. When a newer release of it supports the target, pair that bump with the package instead of carrying a blocker: Phase 4 presents the two together, and they are upgraded or skipped together.

Phase 4: User Confirmation

For each major update, present:

  • Package name and version transition
  • Breaking changes found (summarized)
  • Files potentially affected (count and list)
  • Consumers whose declared ranges block the upgrade, and CI action bumps paired with it, when Phase 3 found any

Use request_user_input to confirm (Codex request_user_input allows up to 3 options per question, so the four actions are split across two questions):

Question 1 — Header: "Decision" Options:

  • Proceed — Continue with upgrades and migrations
  • Show details — Display detailed breaking changes for review
  • Other action — Defer the choice (Skip-package or Abort)

If the user picks Other action, ask a follow-up:

Question 2 — Header: "Other action" Options:

  • Skip package — Exclude a specific package from upgrade
  • Abort — Cancel the upgrade process
  • Cancel — Cancel and return to the previous step

If "Show details" selected, display full migration research, then ask again.

Phase 5: Execute Upgrades

Bump each outdated CI action ref in the file that declares it, under the chosen strategy. For a ref pinned to a commit SHA, resolve the target release tag to the commit it points to (for an annotated tag, follow the tag to its commit) and update the trailing version comment to match. For a tag ref, keep the ref's precision when the action publishes a tag at that precision for the target, otherwise use the full release tag.

After every install command in this phase, run both checks below before any tests and before Phase 6.

  1. Confirm the installed tree moved — spot-check the resolved version of one or two upgraded packages in the installed dependency tree against the manifest. An install can record the new versions while leaving the installed packages on their old ones, which makes every later check report on the pre-upgrade tree. When the two disagree, force a clean resolve: use the package manager's lockfile-respecting install where it has one, otherwise clear the installed tree and install again. Re-check afterward.
  2. Diff the package-manager configuration — inspect the package-manager config files for entries the tool wrote on its own. A tool enforcing a safety guard, such as a minimum age before a release is installable or a provenance requirement, may record a per-package exclusion rather than refusing. Treat such an entry as the guard being bypassed: revert it and lower the manifest constraint to the newest version the guard admits. When the lowered range still admits the rejected version, an existing lockfile keeps it: restore the lockfile from git (delete it when git does not track it), re-run the resolving install and any semver-respecting update command this phase already ran, and diff the configuration again.
Show full SKILL.md (623 more words)Show less
Cautious Strategy

First upgrade minor and patch only using the package manager's semver-respecting update command, then run tests. If the test command exits nonzero, stop before proceeding with major upgrades.

Major Version Upgrades

Update the manifest file (version constraint) and run the install/resolve command. For package managers with a dedicated upgrade command, use it. For others (Swift PM, Maven, Gradle), edit the manifest directly.

Phase 6: Apply Migrations

Step 1: Run Codemods (if Available)

Some ecosystems provide automated migration tools:

EcosystemMigration tools
Reactnpx react-codemod [transform]
Next.jsnpx @next/codemod [transform]
Jestnpx jest-codemods
Angularnpx ng update
Rustcargo fix for edition migrations
Pythonpyupgrade, python-modernize
Step 2: Manual Code Changes

For changes requiring manual intervention:

  1. Read the affected file
  2. Apply the necessary transformation with apply_patch
  3. Show the user what changed
Step 3: Raise Manifest Floors

When migrated code adopts an API that first shipped after the lower bound the manifest declares for that package, raise the constraint to the earliest release that provides every API the migrated code uses, confirmed against the package's tagged source or changelog, then re-run the install so any lockfile records the raised constraint. Passing checks do not clear a stale floor, since they build against the resolved release rather than the floor.

Step 4: Update Configuration Files

If configuration format changed, read current config, transform to new format, write updated config.

Step 5: Sync Version-Pinned CI/Container References

Some packages pin their version outside the manifest, beyond the package manager's reach, so a green local run hides the drift. For every upgraded package (major, minor, or patch), search CI and container configs for the old version string with rg "<old-version>" .github Dockerfile* docker-compose* .devcontainer and bump it in lockstep:

  • CI container images whose tag must track the package — e.g. a Playwright image tag kept in lockstep with the installed @playwright/test version.
  • Base images and tool versions in Dockerfile, .devcontainer/, and docker-compose.yml.
  • Pinned tool versions in CI setup steps (actions/setup-node node-version, setup-python, toolchain files).

Phase 7: Verification

Step 1: Run $run-checks Skill

Run the $run-checks skill to execute the project's verification gate.

Step 2: Exercise Upgraded Schema Against the Real Store

When an upgraded package owns persisted schema, run the test tiers that exercise the real backing store rather than the default command alone. A tier that substitutes test doubles for the store passes on a schema the upgraded package no longer accepts. Diff the schema the package now generates against the one the project has migrated to; when they differ, return to Phase 6 for the migration the difference calls for, then run the $run-checks skill again and re-run the tiers.

Step 3: Report Results

Summarize: packages upgraded (count), CI action refs bumped (count, unverified until the next CI run), breaking changes addressed (count), files modified (count), test results, remaining manual tasks.

Step 4: Recommend Next Steps

If any migrations could not be automated:

  • List specific changes the user needs to review
  • Highlight deprecated patterns that need attention
  • Note any runtime behavior changes to watch for

Error Handling

Discovery Tool Not Available

If the discovery tool is not installed, $review-dependencies will note it. Fall back to manual version checking via web search.

Network Errors During Research

If web search/fetch fails: retry with alternative search terms, provide manual research links, proceed with caution warning that migration research may be incomplete.

Test Failures After Upgrade

Phase 7's gate diagnoses a failing test and applies a fix. When it stops without a root cause:

  • Identify which package likely caused the failure
  • Suggest rollback: restore manifest and lockfile from git, then reinstall
Migration Research Incomplete

If official migration docs are not found: check the package's repository for issues and discussions, note as "migration research incomplete — proceed with caution."

© tobihagemann, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in codex/skills/update-dependencies of tobihagemann/turbo.

Open the folder on GitHubat commit 931eda5

Compare with similar skills

Update Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Dependencies this skilltobihagemann/turbo408—~3kAutomated safety check: PassMIT
CI CD Setuprshankras/claude-code-apple-skills787—~1.5kAutomated safety check: NotesMIT
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
Releasechampionswimmer/pi-context-prune245—~907Automated safety check: PassNone

Similar skills

  • CI CD Setup

    rshankras/claude-code-apple-skills

    Generate CI/CD configuration for automated builds, tests, and distribution of iOS/macOS apps.

    787 GitHub stars~1.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Release

    championswimmer/pi-context-prune

    Creates a repository release for this Pi package. An agent skill from championswimmer/pi-context-prune.

    245 GitHub stars~907 tokensUpdated 10 days ago
    DevOps & CloudAuto-check passed
  • A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…

    871 GitHub stars~2.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from tobihagemann/turbo

All 81 skills in this repo
  • Consult Oracle

    tobihagemann/turbo

    Consult ChatGPT Pro via ChatGPT browser automation for problems that resist standard approaches.

    408 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Fetch PR Comments

    tobihagemann/turbo

    Fetch and summarize review feedback and conversation from a GitHub PR (unresolved review threads, review bodies, and PR conversation comments) without making changes.

    408 GitHub stars~967 tokensUpdated yesterday
    Auto-check passed
  • Recall Rationale

    tobihagemann/turbo

    Recall why a past change was made by locating the Claude Code transcript that produced it.

    408 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Resolve PR Comments

    tobihagemann/turbo

    Evaluate, fix, answer, and reply to GitHub pull request review comments and conversation comments.

    408 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check passed
  • Resolve PR Comments

    tobihagemann/turbo

    Evaluate, fix, answer, and reply to GitHub pull request review comments and conversation comments.

    408 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check passed
  • Assess Technical Debt

    tobihagemann/turbo

    Assess project-wide structural technical debt: complexity hotspots, deprecated API usage, duplication clusters, architecture rot, and low-value tests.

    408 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed

Questions about Update Dependencies

What does Update Dependencies do?

Upgrade project dependencies with breaking change research for major version updates. Update Dependencies is an agent skill from tobihagemann/turbo. Upgrade project dependencies with breaking change research for major version updates.

When should I use Update Dependencies?

Update Dependencies fits situations like: the user asks to update dependencies; upgrade packages; upgrade dependencies; update npm deps.

How do I install Update Dependencies in Claude Code?

Run `npx skills add tobihagemann/turbo --skill update-dependencies -a claude-code`. Or copy the skill folder (codex/skills/update-dependencies in tobihagemann/turbo) into .claude/skills/update-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Update Dependencies in Codex?

Run `npx skills add tobihagemann/turbo --skill update-dependencies -a codex`. Or copy the skill folder (codex/skills/update-dependencies in tobihagemann/turbo) into .agents/skills/update-dependencies in your project. Codex loads it when a task matches its description.

Can I use Update Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tobihagemann/turbo --skill update-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-dependencies, .gemini/skills/update-dependencies, .github/skills/update-dependencies and .opencode/skills/update-dependencies in your project.

What does Update Dependencies need to run?

Going by SKILL.md and its folder, Update Dependencies needs the command-line tools its instructions call (npx, cargo and rg). Our summary lists: Python 3; Node.js; Docker.

Does Update Dependencies access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Dependencies use?

Update Dependencies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Dependencies use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Dependencies?

Skills that share tags, products or a category with Update Dependencies: CI CD Setup (rshankras/claude-code-apple-skills, 787 stars), Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars) and GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Dependencies?

tobihagemann (a GitHub user) maintains it in tobihagemann/turbo, which has 408 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 9, 2026.

Source: tobihagemann/turbo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.