CI CD Setup
rshankras/claude-code-apple-skills
Generate CI/CD configuration for automated builds, tests, and distribution of iOS/macOS apps.
Upgrade project dependencies with breaking change research for major version updates.
$ npx skills add tobihagemann/turbo --skill update-dependencies -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tobihagemann/turbo update-dependencies --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tobihagemann/turbo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/codex/skills/update-dependencies .claude/skills/update-dependencies && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "update-dependencies" agent skill from https://github.com/tobihagemann/turbo/tree/main/codex/skills/update-dependencies into .claude/skills/update-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-dependencies", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tobihagemann/turbo/tree/main/codex/skills/update-dependenciesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tobihagemann/turbo --skill update-dependencies -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tobihagemann/turbo update-dependencies --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tobihagemann/turbo.git skills-src && mkdir -p .agents/skills && cp -r skills-src/codex/skills/update-dependencies .agents/skills/update-dependencies && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "update-dependencies" agent skill from https://github.com/tobihagemann/turbo/tree/main/codex/skills/update-dependencies into .agents/skills/update-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-dependencies", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tobihagemann/turbo --skill update-dependencies -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tobihagemann/turbo update-dependencies --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tobihagemann/turbo.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/codex/skills/update-dependencies .cursor/skills/update-dependencies && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "update-dependencies" agent skill from https://github.com/tobihagemann/turbo/tree/main/codex/skills/update-dependencies into .cursor/skills/update-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-dependencies", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tobihagemann/turbo.git --path codex/skills/update-dependencies--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tobihagemann/turbo --skill update-dependencies -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tobihagemann/turbo update-dependencies --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tobihagemann/turbo.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/codex/skills/update-dependencies .gemini/skills/update-dependencies && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "update-dependencies" agent skill from https://github.com/tobihagemann/turbo/tree/main/codex/skills/update-dependencies into .gemini/skills/update-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-dependencies", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tobihagemann/turbo update-dependenciesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tobihagemann/turbo --skill update-dependencies -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tobihagemann/turbo.git skills-src && mkdir -p .github/skills && cp -r skills-src/codex/skills/update-dependencies .github/skills/update-dependencies && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "update-dependencies" agent skill from https://github.com/tobihagemann/turbo/tree/main/codex/skills/update-dependencies into .github/skills/update-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-dependencies", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tobihagemann/turbo --skill update-dependencies -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tobihagemann/turbo update-dependencies --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tobihagemann/turbo.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/codex/skills/update-dependencies .opencode/skills/update-dependencies && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "update-dependencies" agent skill from https://github.com/tobihagemann/turbo/tree/main/codex/skills/update-dependencies into .opencode/skills/update-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-dependencies", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
update-dependenciesUpgrade project dependencies with breaking change research for major version updates.
Update Dependencies is an agent skill from tobihagemann/turbo. Upgrade project dependencies with breaking change research for major version updates. Use when the user asks to "update dependencies", "upgrade packages", "upgrade dependencies", "update deps", "upgrade deps", "update npm deps", "update Swift packages", "cargo update", "go get updates", "bundle update", "pip upgrade", or "update GitHub Actions".
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering iOS development, CI/CD and Code migrations. It works with GitHub Actions and npm. The repository describes itself as: Reusable workflows for planning, building, reviewing, and shipping with Claude Code and Codex. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 931eda5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxcargorgFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Update Dependencies loads about 3k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 1,644 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tobihagemann/turbo at commit 931eda5, republished under its MIT licence (© tobihagemann). 1,644 words, ~2,959 tokens.
.claude/skills/update-dependencies/SKILL.md (or your agent's skills folder).Upgrade project dependencies, researching breaking changes for major version updates.
Optional filter: $ARGUMENTS (e.g., react, Alamofire, serde tokio)
At the start, use update_plan to track each phase, restating any remaining steps of a parent workflow alongside them:
$review-dependencies skill$run-checks skillRun the $review-dependencies skill to detect package managers and discover available updates. If no updates are available, stop.
Before summarizing, set aside packages whose version tracks a pinned runtime or platform rather than the newest release, such as runtime type definitions and platform SDKs. Find the pin the project declares (version manager file, engines field, container base image, CI setup step) and hold any version beyond it until the pin moves.
Present a summary showing:
Use request_user_input for upgrade strategy (Codex request_user_input allows up to 3 options per question, so the strategies are split across two questions):
Question 1 — Header: "Approach" Options:
When a major upgrade would force a migration that is costly to reverse, present a Get a second opinion option in place of All at once, keeping Question 1 at three options and leaving Major handling in place so Question 2 stays reachable. It runs the $consult-claude skill for which strategy the breaking changes warrant. Then resolve the strategy with that answer in hand, re-asking when the choice stays the user's. A freeform answer asking to upgrade everything together selects the All-at-once strategy.
If the user picks Major handling, ask a follow-up:
Question 2 — Header: "Major handling" Options:
For each package or CI action with a major version update:
Identify all major versions between current and target. For example:
react: 17.0.2 → 19.0.0 → research v18 AND v19 breaking changesAlamofire: 4.9.1 → 6.0.0 → research v5 AND v6 breaking changesSearch for migration documentation:
Web search: "[package-name] v[X] migration guide"
Web search: "[package-name] v[X] breaking changes"Common sources: GitHub releases page, official docs, changelog files.
Identify: API changes (renamed/removed functions), configuration changes, peer/transitive dependency requirements, behavioral changes, deprecated features now removed.
Use rg to find usage of deprecated or changed APIs. Document which files are affected and what changes are needed.
Then check the package's installed consumers: read their declared peer or compatibility ranges and flag any range that excludes the target version. Toolchain consumers such as linters, type checkers, and build tooling can block a major even when the project's own code and configuration are clean. Carry each one into Phase 4 as a blocker.
A CI action that installs or runs the package counts as such a consumer. When a newer release of it supports the target, pair that bump with the package instead of carrying a blocker: Phase 4 presents the two together, and they are upgraded or skipped together.
For each major update, present:
Use request_user_input to confirm (Codex request_user_input allows up to 3 options per question, so the four actions are split across two questions):
Question 1 — Header: "Decision" Options:
If the user picks Other action, ask a follow-up:
Question 2 — Header: "Other action" Options:
If "Show details" selected, display full migration research, then ask again.
Bump each outdated CI action ref in the file that declares it, under the chosen strategy. For a ref pinned to a commit SHA, resolve the target release tag to the commit it points to (for an annotated tag, follow the tag to its commit) and update the trailing version comment to match. For a tag ref, keep the ref's precision when the action publishes a tag at that precision for the target, otherwise use the full release tag.
After every install command in this phase, run both checks below before any tests and before Phase 6.
First upgrade minor and patch only using the package manager's semver-respecting update command, then run tests. If the test command exits nonzero, stop before proceeding with major upgrades.
Update the manifest file (version constraint) and run the install/resolve command. For package managers with a dedicated upgrade command, use it. For others (Swift PM, Maven, Gradle), edit the manifest directly.
Some ecosystems provide automated migration tools:
| Ecosystem | Migration tools |
|---|---|
| React | npx react-codemod [transform] |
| Next.js | npx @next/codemod [transform] |
| Jest | npx jest-codemods |
| Angular | npx ng update |
| Rust | cargo fix for edition migrations |
| Python | pyupgrade, python-modernize |
For changes requiring manual intervention:
apply_patchWhen migrated code adopts an API that first shipped after the lower bound the manifest declares for that package, raise the constraint to the earliest release that provides every API the migrated code uses, confirmed against the package's tagged source or changelog, then re-run the install so any lockfile records the raised constraint. Passing checks do not clear a stale floor, since they build against the resolved release rather than the floor.
If configuration format changed, read current config, transform to new format, write updated config.
Some packages pin their version outside the manifest, beyond the package manager's reach, so a green local run hides the drift. For every upgraded package (major, minor, or patch), search CI and container configs for the old version string with rg "<old-version>" .github Dockerfile* docker-compose* .devcontainer and bump it in lockstep:
@playwright/test version.Dockerfile, .devcontainer/, and docker-compose.yml.actions/setup-node node-version, setup-python, toolchain files).$run-checks SkillRun the $run-checks skill to execute the project's verification gate.
When an upgraded package owns persisted schema, run the test tiers that exercise the real backing store rather than the default command alone. A tier that substitutes test doubles for the store passes on a schema the upgraded package no longer accepts. Diff the schema the package now generates against the one the project has migrated to; when they differ, return to Phase 6 for the migration the difference calls for, then run the $run-checks skill again and re-run the tiers.
Summarize: packages upgraded (count), CI action refs bumped (count, unverified until the next CI run), breaking changes addressed (count), files modified (count), test results, remaining manual tasks.
If any migrations could not be automated:
If the discovery tool is not installed, $review-dependencies will note it. Fall back to manual version checking via web search.
If web search/fetch fails: retry with alternative search terms, provide manual research links, proceed with caution warning that migration research may be incomplete.
Phase 7's gate diagnoses a failing test and applies a fix. When it stops without a root cause:
If official migration docs are not found: check the package's repository for issues and discussions, note as "migration research incomplete — proceed with caution."
© tobihagemann, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in codex/skills/update-dependencies of tobihagemann/turbo.
Open the folder on GitHubat commit 931eda5
Update Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Update Dependencies this skilltobihagemann/turbo | 408 | — | ~3k | Automated safety check: Pass | MIT | |
| CI CD Setuprshankras/claude-code-apple-skills | 787 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Repo Hygiene Scan and FixQwenLM/qwen-code | 28k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| CI Pipeline Synthesizerkajisho5/ffmpeg-skill | 1.9k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| GitHub Actions Supply Chain Pinningasyncapi/generator | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Releasechampionswimmer/pi-context-prune | 245 | — | ~907 | Automated safety check: Pass | None |
rshankras/claude-code-apple-skills
Generate CI/CD configuration for automated builds, tests, and distribution of iOS/macOS apps.
QwenLM/qwen-code
Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.
kajisho5/ffmpeg-skill
Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.
asyncapi/generator
A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).
championswimmer/pi-context-prune
Creates a repository release for this Pi package. An agent skill from championswimmer/pi-context-prune.
jmfederico/pi-web
A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…
tobihagemann/turbo
Consult ChatGPT Pro via ChatGPT browser automation for problems that resist standard approaches.
tobihagemann/turbo
Fetch and summarize review feedback and conversation from a GitHub PR (unresolved review threads, review bodies, and PR conversation comments) without making changes.
tobihagemann/turbo
Recall why a past change was made by locating the Claude Code transcript that produced it.
tobihagemann/turbo
Evaluate, fix, answer, and reply to GitHub pull request review comments and conversation comments.
tobihagemann/turbo
Evaluate, fix, answer, and reply to GitHub pull request review comments and conversation comments.
tobihagemann/turbo
Assess project-wide structural technical debt: complexity hotspots, deprecated API usage, duplication clusters, architecture rot, and low-value tests.
Works with
Categories
Upgrade project dependencies with breaking change research for major version updates. Update Dependencies is an agent skill from tobihagemann/turbo. Upgrade project dependencies with breaking change research for major version updates.
Update Dependencies fits situations like: the user asks to update dependencies; upgrade packages; upgrade dependencies; update npm deps.
Run `npx skills add tobihagemann/turbo --skill update-dependencies -a claude-code`. Or copy the skill folder (codex/skills/update-dependencies in tobihagemann/turbo) into .claude/skills/update-dependencies in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tobihagemann/turbo --skill update-dependencies -a codex`. Or copy the skill folder (codex/skills/update-dependencies in tobihagemann/turbo) into .agents/skills/update-dependencies in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tobihagemann/turbo --skill update-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-dependencies, .gemini/skills/update-dependencies, .github/skills/update-dependencies and .opencode/skills/update-dependencies in your project.
Going by SKILL.md and its folder, Update Dependencies needs the command-line tools its instructions call (npx, cargo and rg). Our summary lists: Python 3; Node.js; Docker.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Update Dependencies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Update Dependencies: CI CD Setup (rshankras/claude-code-apple-skills, 787 stars), Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars) and GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tobihagemann (a GitHub user) maintains it in tobihagemann/turbo, which has 408 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 9, 2026.
Source: tobihagemann/turbo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.