← ClaudeAtlas

upgrade-depslisted

Audit outdated npm/yarn/pnpm dependencies across a monorepo — security-advisory exploitability, transitive conflicts, real call-site usage, and targeted changelog review for major bumps — then publish issues (batched for trivial in-range bumps, one per package or coupled group otherwise; every major-version bump defaults to ready-for-human, minor/patch range-edits stay ready-for-agent unless a conflict or advisory can't be resolved cleanly) with required test additions and a safety checklist, for crew-afk or solve-issue to execute. Use when the user wants to upgrade dependencies, audit outdated packages, or plan a safe dependency bump. Does not perform the upgrade itself.
ypxing/coding-crew · ★ 1 · AI & Automation · score 64
Install: claude install-skill ypxing/coding-crew
# Upgrade Deps Plan safe dependency upgrades and hand them off as issues. This skill never edits `package.json`/lockfiles or runs the upgrade itself — it analyzes, then files work for `solve-issue` / `crew-afk` to execute. Ecosystem support: npm, yarn, pnpm (Node.js). If the repo uses another package manager, stop and ask the user before proceeding. {{FRAGMENT:tracker-configuration}} Before running any package-manager command (`outdated`, `audit`, `ls`/`why`, or a later reinstall), use the `dep-install` skill first to detect and lock the session's install mode. Every command in this skill — not just install — must then run in that mode: if the project is docker-mode, `outdated`/`audit`/`ls`/`why` run inside the container via the same mechanism as `test`/`lint`/`typecheck` in `dev-commands.json`, never against the host's `node_modules`, which may not even exist there. Also resolve the `typecheck` field from `.coding-crew/dev-commands.json` now, using the same discovery/cache mechanism `add-tests` uses for its own fields (`bash scripts/discover-commands.sh`, then `write-commands-cache.sh` if it prompts). Step 6 needs this to get a mechanical breaking-change signal on major bumps; if it resolves to `null`, that step falls back to changelog review alone for every major bump — say so when it happens rather than silently skipping the signal. ## Process ### 1. Determine feature slug Default to `.scratch/deps-upgrade/`. If it already has issues, ask the user whether to reuse