Agent skill

Dependency Upgrade

by sangrokjung in sangrokjung/claude-forge

Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing.

MITAuto-check passedTesting & QA

Install Dependency Upgrade

skills CLI
$ npx skills add sangrokjung/claude-forge --skill dependency-upgrade -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sangrokjung/claude-forge dependency-upgrade --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sangrokjung/claude-forge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-upgrade .claude/skills/dependency-upgrade && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-upgrade
GitHub stars
850
Used in
12 other repos
Token cost
~2.3k tokens
SKILL.md length
233 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing.

  • Works in 3 steps: Planning → Incremental Updates → Validation
  • Upgrading framework versions
  • SKILL.md covers When to Use This Skill, Semantic Versioning Review, Dependency Analysis and Compatibility Matrix, plus 8 more sections
  • Calls npm, yarn and npx; reaches raw.githubusercontent.com

What it does

Dependency Upgrade is an agent skill from sangrokjung/claude-forge. Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing. Use when upgrading framework versions, updating major dependencies, or managing breaking changes in libraries.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Code migrations and Dependency management. The repository describes itself as: oh-my-zsh for Claude Code — 16 agents, 35 commands, 32 skills, 21 safety hooks in one install. v4.0 adds an adversarial review loop: a second agent that never sees the first… The licence is MIT.

When your agent uses it

  • Upgrading framework versions
  • Updating major dependencies
  • Managing breaking changes in libraries

Example prompts

  • “/dependency-upgrade”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Planning
  2. Incremental Updates
  3. Validation

What it can do on your machine

Read from SKILL.md and the folder at commit 34d881d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • yarn
    • npx
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Upgrade loads about 2.3k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 233 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sangrokjung/claude-forge at commit 34d881d, republished under its MIT licence (© sangrokjung). 233 words, ~2,274 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-upgrade/SKILL.md (or your agent's skills folder).
name
dependency-upgrade
description
Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing. Use when upgrading framework versions, updating major dependencies, or managing breaking changes in libraries.

Dependency Upgrade

Master major dependency version upgrades, compatibility analysis, staged upgrade strategies, and comprehensive testing approaches.

When to Use This Skill

  • Upgrading major framework versions
  • Updating security-vulnerable dependencies
  • Modernizing legacy dependencies
  • Resolving dependency conflicts
  • Planning incremental upgrade paths
  • Testing compatibility matrices
  • Automating dependency updates

Semantic Versioning Review

MAJOR.MINOR.PATCH (e.g., 2.3.1)

MAJOR: Breaking changes
MINOR: New features, backward compatible
PATCH: Bug fixes, backward compatible

^2.3.1 = >=2.3.1 <3.0.0 (minor updates)
~2.3.1 = >=2.3.1 <2.4.0 (patch updates)
2.3.1 = exact version

Dependency Analysis

Audit Dependencies
bash
# npm
npm outdated
npm audit
npm audit fix

# yarn
yarn outdated
yarn audit

# Check for major updates
npx npm-check-updates
npx npm-check-updates -u  # Update package.json
Analyze Dependency Tree
bash
# See why a package is installed
npm ls package-name
yarn why package-name

# Find duplicate packages
npm dedupe
yarn dedupe

# Visualize dependencies
npx madge --image graph.png src/

Compatibility Matrix

javascript
// compatibility-matrix.js
const compatibilityMatrix = {
  react: {
    "16.x": {
      "react-dom": "^16.0.0",
      "react-router-dom": "^5.0.0",
      "@testing-library/react": "^11.0.0",
    },
    "17.x": {
      "react-dom": "^17.0.0",
      "react-router-dom": "^5.0.0 || ^6.0.0",
      "@testing-library/react": "^12.0.0",
    },
    "18.x": {
      "react-dom": "^18.0.0",
      "react-router-dom": "^6.0.0",
      "@testing-library/react": "^13.0.0",
    },
  },
};

function checkCompatibility(packages) {
  // Validate package versions against matrix
}

Staged Upgrade Strategy

Phase 1: Planning
bash
# 1. Identify current versions
npm list --depth=0

# 2. Check for breaking changes
# Read CHANGELOG.md and MIGRATION.md

# 3. Create upgrade plan
echo "Upgrade order:
1. TypeScript
2. React
3. React Router
4. Testing libraries
5. Build tools" > UPGRADE_PLAN.md
Phase 2: Incremental Updates
bash
# Don't upgrade everything at once!

# Step 1: Update TypeScript
npm install typescript@latest

# Test
npm run test
npm run build

# Step 2: Update React (one major version at a time)
npm install react@17 react-dom@17

# Test again
npm run test

# Step 3: Continue with other packages
npm install react-router-dom@6

# And so on...
Phase 3: Validation
javascript
// tests/compatibility.test.js
describe("Dependency Compatibility", () => {
  it("should have compatible React versions", () => {
    const reactVersion = require("react/package.json").version;
    const reactDomVersion = require("react-dom/package.json").version;

    expect(reactVersion).toBe(reactDomVersion);
  });

  it("should not have peer dependency warnings", () => {
    // Run npm ls and check for warnings
  });
});

Breaking Change Handling

Identifying Breaking Changes
bash
# Use changelog parsers
npx changelog-parser react 16.0.0 17.0.0

# Or manually check
curl https://raw.githubusercontent.com/facebook/react/main/CHANGELOG.md
Codemod for Automated Fixes
bash
# React upgrade codemods
npx react-codeshift <transform> <path>

# Example: Update lifecycle methods
npx react-codeshift \
  --parser tsx \
  --transform react-codeshift/transforms/rename-unsafe-lifecycles.js \
  src/
Custom Migration Script
javascript
// migration-script.js
const fs = require("fs");
const glob = require("glob");

glob("src/**/*.tsx", (err, files) => {
  files.forEach((file) => {
    let content = fs.readFileSync(file, "utf8");

    // Replace old API with new API
    content = content.replace(
      /componentWillMount/g,
      "UNSAFE_componentWillMount",
    );

    // Update imports
    content = content.replace(
      /import { Component } from 'react'/g,
      "import React, { Component } from 'react'",
    );

    fs.writeFileSync(file, content);
  });
});

Testing Strategy

Unit Tests
javascript
// Ensure tests pass before and after upgrade
npm run test

// Update test utilities if needed
npm install @testing-library/react@latest
Integration Tests
javascript
// tests/integration/app.test.js
describe("App Integration", () => {
  it("should render without crashing", () => {
    render(<App />);
  });

  it("should handle navigation", () => {
    const { getByText } = render(<App />);
    fireEvent.click(getByText("Navigate"));
    expect(screen.getByText("New Page")).toBeInTheDocument();
  });
});
Visual Regression Tests
javascript
// visual-regression.test.js
describe("Visual Regression", () => {
  it("should match snapshot", () => {
    const { container } = render(<App />);
    expect(container.firstChild).toMatchSnapshot();
  });
});
E2E Tests
javascript
// cypress/e2e/app.cy.js
describe("E2E Tests", () => {
  it("should complete user flow", () => {
    cy.visit("/");
    cy.get('[data-testid="login"]').click();
    cy.get('input[name="email"]').type("user@example.com");
    cy.get('button[type="submit"]').click();
    cy.url().should("include", "/dashboard");
  });
});

Automated Dependency Updates

Renovate Configuration
json
// renovate.json
{
  "extends": ["config:base"],
  "packageRules": [
    {
      "matchUpdateTypes": ["minor", "patch"],
      "automerge": true
    },
    {
      "matchUpdateTypes": ["major"],
      "automerge": false,
      "labels": ["major-update"]
    }
  ],
  "schedule": ["before 3am on Monday"],
  "timezone": "America/New_York"
}
Dependabot Configuration
yaml
# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
    open-pull-requests-limit: 5
    reviewers:
      - "team-leads"
    commit-message:
      prefix: "chore"
      include: "scope"

Rollback Plan

javascript
// rollback.sh
#!/bin/bash

# Save current state
git stash
git checkout -b upgrade-branch

# Attempt upgrade
npm install package@latest

# Run tests
if npm run test; then
  echo "Upgrade successful"
  git add package.json package-lock.json
  git commit -m "chore: upgrade package"
else
  echo "Upgrade failed, rolling back"
  git checkout main
  git branch -D upgrade-branch
  npm install  # Restore from package-lock.json
fi

Common Upgrade Patterns

Lock File Management
bash
# npm
npm install --package-lock-only  # Update lock file only
npm ci  # Clean install from lock file

# yarn
yarn install --frozen-lockfile  # CI mode
yarn upgrade-interactive  # Interactive upgrades
Peer Dependency Resolution
bash
# npm 7+: strict peer dependencies
npm install --legacy-peer-deps  # Ignore peer deps

# npm 8+: override peer dependencies
npm install --force
Workspace Upgrades
bash
# Update all workspace packages
npm install --workspaces

# Update specific workspace
npm install package@latest --workspace=packages/app

Resources

  • references/semver.md: Semantic versioning guide
  • references/compatibility-matrix.md: Common compatibility issues
  • references/staged-upgrades.md: Incremental upgrade strategies
  • references/testing-strategy.md: Comprehensive testing approaches
  • assets/upgrade-checklist.md: Step-by-step checklist
  • assets/compatibility-matrix.csv: Version compatibility table
  • scripts/audit-dependencies.sh: Dependency audit script

Best Practices

  1. Read Changelogs: Understand what changed
  2. Upgrade Incrementally: One major version at a time
  3. Test Thoroughly: Unit, integration, E2E tests
  4. Check Peer Dependencies: Resolve conflicts early
  5. Use Lock Files: Ensure reproducible installs
  6. Automate Updates: Use Renovate or Dependabot
  7. Monitor: Watch for runtime errors post-upgrade
  8. Document: Keep upgrade notes

Upgrade Checklist

markdown
Pre-Upgrade:

- [ ] Review current dependency versions
- [ ] Read changelogs for breaking changes
- [ ] Create feature branch
- [ ] Backup current state (git tag)
- [ ] Run full test suite (baseline)

During Upgrade:

- [ ] Upgrade one dependency at a time
- [ ] Update peer dependencies
- [ ] Fix TypeScript errors
- [ ] Update tests if needed
- [ ] Run test suite after each upgrade
- [ ] Check bundle size impact

Post-Upgrade:

- [ ] Full regression testing
- [ ] Performance testing
- [ ] Update documentation
- [ ] Deploy to staging
- [ ] Monitor for errors
- [ ] Deploy to production

Common Pitfalls

  • Upgrading all dependencies at once
  • Not testing after each upgrade
  • Ignoring peer dependency warnings
  • Forgetting to update lock file
  • Not reading breaking change notes
  • Skipping major versions
  • Not having rollback plan

© sangrokjung, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dependency-upgrade of sangrokjung/claude-forge.

Open the folder on GitHubat commit 34d881d

Used in 12 other repositories

We found 29 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 12 other GitHub owners. This page covers the copy in sangrokjung/claude-forge, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Dependency Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Upgrade compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Upgrade this skillsangrokjung/claude-forge85012 repos~2.3kAutomated safety check: PassMIT
OBS Plugin Dependency Upgradesorayuki/obs-multi-rtmp5.1k—~609Automated safety check: PassGPL-2.0
CLIProxy Core Synccaidaoli/ccLoad418—~1.5kAutomated safety check: PassMIT
Rails Upgrade Assistantombulabs/claude-code_rails-upgrade-skill389—~2.7kAutomated safety check: PassMIT
Breaking Change Analysisruby-git/ruby-git1.8k—~1.7kAutomated safety check: PassMIT
Laravel Package Major Upgrademailcarrierapp/mailcarrier164—~1.1kAutomated safety check: PassMIT

Similar skills

  • OBS Plugin Dependency Upgrade

    sorayuki/obs-multi-rtmp

    Updates the obs-multi-rtmp plugin repo to the latest upstream plugin template and OBS Studio version, including dependency metadata, then rebuilds it with CMake.

    5.1k GitHub stars~609 tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • CLIProxy Core Sync

    caidaoli/ccLoad

    Syncs or audits ccLoad's CLIProxyAPI protocol-conversion core and registered provider adapters against one pinned upstream commit, then verifies the result.

    418 GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Rails Upgrade Assistant

    ombulabs/claude-code_rails-upgrade-skill

    Analyzes a Rails app and builds an upgrade report with breaking changes, deprecations and step-by-step migration guides, one version at a time from Rails 2.3 through 8.1.

    389 GitHub stars~2.7k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Breaking Change Analysis

    ruby-git/ruby-git

    Assesses what an API change would break before it is made, finds every usage, documents the impact and plans a deprecation or migration path.

    1.8k GitHub stars~1.7k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Laravel Package Major Upgrade

    mailcarrierapp/mailcarrier

    Adds support for a new Laravel major to a package by extending composer.json constraints for illuminate, Testbench and Pest and the CI test matrix.

    164 GitHub stars~1.1k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • WxJava Upgrade Guide

    binarywang/WxJava

    Plans a WxJava version upgrade, checking the BOM, module dependencies, JDK version and configuration, with phased steps and clear rollback conditions.

    33k GitHub stars~129 tokensUpdated 12 days ago
    DevelopmentAuto-check passed

More from sangrokjung/claude-forge

All 24 skills in this repo
  • Debugging Strategies

    sangrokjung/claude-forge

    Master systematic debugging techniques, profiling tools, and root cause analysis to efficiently track down bugs across any codebase or technology stack.

    850 GitHub starsUsed in 13 repos~3.1k tokens
    Auto-check passed
  • Skill Factory

    sangrokjung/claude-forge

    Analyze session work and automatically convert reusable patterns into Claude Code skills.

    850 GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Cc Dev Agent

    sangrokjung/claude-forge

    A skill your agent uses when starting Claude Code projects, writing CLAUDE.md/spec.md, dispatching subagents, or requesting Agent Teams parallel development.

    850 GitHub stars~771 tokensUpdated 1 mo ago
    Auto-check passed
  • Continuous Learning V2

    sangrokjung/claude-forge

    Instinct-based learning system that observes sessions via hooks, creates atomic instincts with confidence scoring, and evolves them into skills/commands/agents.

    850 GitHub starsUsed in 6 repos~1.8k tokens
    Auto-check passed
  • Harness Diet

    sangrokjung/claude-forge

    Measure and shrink the always-loaded context of a Claude Code harness (CLAUDE.md + rules without paths frontmatter) back under budget — migrate narrative to reference files, convert rules to…

    850 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Session Wrap

    sangrokjung/claude-forge

    A skill your agent uses when wrapping up a session before ending.

    850 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Dependency Upgrade

What does Dependency Upgrade do?

Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing. Dependency Upgrade is an agent skill from sangrokjung/claude-forge. Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing.

When should I use Dependency Upgrade?

Dependency Upgrade fits situations like: upgrading framework versions; updating major dependencies; managing breaking changes in libraries.

How do I install Dependency Upgrade in Claude Code?

Run `npx skills add sangrokjung/claude-forge --skill dependency-upgrade -a claude-code`. Or copy the skill folder (skills/dependency-upgrade in sangrokjung/claude-forge) into .claude/skills/dependency-upgrade in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Upgrade in Codex?

Run `npx skills add sangrokjung/claude-forge --skill dependency-upgrade -a codex`. Or copy the skill folder (skills/dependency-upgrade in sangrokjung/claude-forge) into .agents/skills/dependency-upgrade in your project. Codex loads it when a task matches its description.

Can I use Dependency Upgrade in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sangrokjung/claude-forge --skill dependency-upgrade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-upgrade, .gemini/skills/dependency-upgrade, .github/skills/dependency-upgrade and .opencode/skills/dependency-upgrade in your project.

What does Dependency Upgrade need to run?

Going by SKILL.md and its folder, Dependency Upgrade needs the command-line tools its instructions call (npm, yarn, npx and curl). Our summary lists: Node.js.

Does Dependency Upgrade access the network?

SKILL.md names 1 domain. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Dependency Upgrade safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Upgrade use?

Dependency Upgrade is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Upgrade use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Upgrade?

Skills that share tags, products or a category with Dependency Upgrade: OBS Plugin Dependency Upgrade (sorayuki/obs-multi-rtmp, 5.1k stars), CLIProxy Core Sync (caidaoli/ccLoad, 418 stars), Rails Upgrade Assistant (ombulabs/claude-code_rails-upgrade-skill, 389 stars) and Breaking Change Analysis (ruby-git/ruby-git, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Upgrade?

sangrokjung (a GitHub user) maintains it in sangrokjung/claude-forge, which has 850 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on September 3, 2026.

Source: sangrokjung/claude-forge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.