PluginBench
Skill
Review
Audit score 70

bump-deps

paulrberg/agent-skills

Batch npm/pnpm/yarn/bun dependency updates with structured planning and validation.

What is bump-deps?

Bump-deps uses Taze to create a structured update plan, automatically apply compatible minor/patch updates, and present major-version changes for review. Use it when you need to update dependencies safely while catching incompatibilities before they reach your codebase.

  • Generate a structured dependency update plan classifying each package as apply, review-major, review, or skip-fixed
  • Automatically apply compatible ranged minor and patch updates
  • Present major-version updates in a batch for user review with migration notes
  • Validate the baseline dependency state against the repository's test, build, lint, and type-check suite before making changes
  • Support monorepos, locked versions, Bun catalogs, and package-manager age gates
  • Rerun verification checks after updates and block completion until all issues are resolved

How to install bump-deps

npx skills add https://github.com/paulrberg/agent-skills --skill bump-deps
Prerequisites
  • Node.js project with npm, pnpm, yarn, or Bun package manager
  • Taze installed or available in the repository
  • Standard validation commands (test, build, lint, typecheck) configured in the repository
Claude Code
Cursor
Windsurf
Cline

How to use bump-deps

  1. 1.Run the skill with optional `--dry-run` flag and package names to generate an update plan
  2. 2.Review the structured plan showing current versions, target versions, and update classifications
  3. 3.Approve or reject major-version updates presented in the decision batch
  4. 4.The skill validates the baseline state, applies selected updates, regenerates lockfiles, and reruns verification checks
  5. 5.Review the final diff and any remaining issues before completion

Use cases

Good for
  • Update all minor and patch versions in a project while manually approving major-version bumps
  • Scan a monorepo for outdated dependencies and generate a dry-run plan without modifying files
  • Apply dependency updates to specific packages only using package filters
  • Validate that a dependency update doesn't break builds, tests, or type checking before committing
  • Update Bun catalog entries alongside manifest and lockfile changes
Who it's for
  • Node.js/TypeScript developers managing npm, pnpm, yarn, or Bun workspaces
  • Maintainers of monorepos needing coordinated dependency updates
  • Teams requiring validation that dependency changes don't introduce regressions

bump-deps FAQ

What does --dry-run do?

Generates and displays the structured update plan with counts and a table, but makes no changes to manifests or lockfiles.

Can I update only specific packages?

Yes, pass package names as arguments to constrain both the scan and write phases to those packages only.

What happens if the baseline validation fails?

The skill stops and reports the pre-existing issues without modifying any files, asking you to resolve them first.

Does it handle monorepos?

Yes, it detects monorepos, includes locked versions during scans, and applies updates across all workspaces.

What if an update breaks my build or tests?

The skill reruns your verification suite after updates and blocks completion, presenting all issues for you to fix or revert the offending update.

Full instructions (SKILL.md)

Source of truth, from paulrberg/agent-skills.


argument-hint: "[--dry-run] [package ...]" disable-model-invocation: false effort: medium model: sonnet name: bump-deps user-invocable: true description: "Use for dependency updates: bump npm/pnpm/yarn/bun packages, check outdated, or run taze."

Bump Dependencies

Use Taze to build one structured update plan, apply compatible ranged updates, and make major-version decisions as a batch.

Workflow

  1. Resolve the skill directory and save the helper plan from the target repository:

    bash <skill-dir>/scripts/run-taze.sh --plan [--include package-a,package-b] > <taze-plan.json>
    

    The JSON plan classifies every discovered update as apply, review-major, review, or skip-fixed. The helper detects monorepos, includes locked versions during scans, and mirrors Bun minimum-release-age settings. If the repository uses package-manager age gates or Bun catalogs, read references/conditional-workflows.md for that active branch only.

  2. If --dry-run was requested, present the plan and counts, then stop without changing manifests or lockfiles.

  3. Select every ranged minor/patch update marked apply. Never auto-approve a major package by name. Present all review-major and unknown updates in one decision batch with current version, target version, package role when discoverable, and relevant migration/release notes. Apply only the majors the user selects.

  4. If nothing is selected, report the no-op and stop. If the root manifest uses Bun catalogs, preview the exact selected catalog transitions from the accepted plan:

    uv run <skill-dir>/scripts/update-bun-catalogs.py \
      --root <repo> --plan <taze-plan.json> --include package-a,package-b
    

    The preview is read-only. Missing catalog entries, conflicting plan rows, unsupported versions, or a catalog value that no longer matches the plan fail before writes. The helper does not select upgrades.

  5. Before the first manifest or lockfile write, discover and run the repository's standard validation suite against the existing dependency state. Prefer its advertised aggregate check; otherwise run every exposed dependency-resolution, build, test, typecheck, lint, formatting-check, codegen-check, and repository-invariant command. Use frozen or non-writing modes where available, and record the exact commands for the post-bump rerun. Command failures, dependency or peer-resolution conflicts, and actionable warnings that signal incompatibility or unsafe behavior block the bump; informational notices such as unavoidable deprecations do not. If the baseline has any blocking issue, stop with ### ⛔ Dependency bump blocked — baseline failed, show the exact commands and diagnostics, and ask the user to resolve the pre-existing issues. Do not modify manifests, lockfiles, source, or configuration.

  6. Write all selected Taze updates in one command:

    bash <skill-dir>/scripts/run-taze.sh --write --include package-a,package-b
    
  7. For Bun catalogs, rerun update-bun-catalogs.py with the same plan and include set plus --write. It atomically updates every matching default/named catalog occurrence and preserves each existing ^, ~, or empty prefix. Then run ni so the repository's package manager updates its lockfile.

  8. Inspect the manifest and lockfile diff. Rerun the exact baseline commands, plus the narrowest checks that exercise the updated dependencies and any required migrations. Treat every newly introduced error, type issue, check failure (including tests, builds, lint, formatting, codegen, and repository invariants), dependency or peer-resolution conflict, and actionable compatibility or safety warning as caused by the bump unless evidence shows otherwise.

  9. Fix every issue caused by the bump, including required source or configuration migrations, while preserving intended behavior. Do not suppress diagnostics, weaken validation, or change expected behavior merely to make checks pass. After each fix, rerun the affected check, then rerun the complete recorded suite until it passes. If no clear safe fix exists within the task's authority, stop with ### ⚠️ Dependency regression decision required. Present all such issues in one table with the evidence, affected locations, fix and revert options, and likely effects. Do not report completion until the user chooses, the fix is applied or the offending update is reverted, the lockfile is regenerated, and the complete suite passes.

User-Facing Output

Present plans as ### 📦 Dependency plan with counts and a compact table:

IDPlan valueDecisionPackageCurrent → targetTypeNotes

Use the plan's exact apply, review-major, review, and skip-fixed values alongside plain-language decisions. Assign stable IDs to rows needing a choice so the user can answer once. Use ### 🔎 Dry run — no files written for a preview and ### ✅ No selected updates for a no-op.

Finish applied work with ### 🏁 Dependencies updated, a tree of changed manifests/lockfiles, and ### 🧪 Verification. Use ### ⚠️ Remaining review only for non-blocking informational matters, never for an unresolved issue caused by the bump. Keep helper JSON, package/version strings, commands, and diagnostics exact and undecorated.

Invariants

  • Fixed versions and non-semver protocols remain unchanged unless the user explicitly asks otherwise.
  • Package arguments constrain both scan and write phases.
  • The same maturity-period policy applies to scan and write.
  • Bun catalog preview and write use the same accepted Taze plan and selected package set; stale plans never write.
  • Do not infer compatibility from SemVer alone when repository evidence, peer ranges, or release notes indicate otherwise.

Completion requires a clean pre-write baseline, a reviewed plan, the retained selected updates, a regenerated lockfile, a passing rerun of the recorded suite and dependency-specific checks, and no unresolved issue caused by the bump. Dry-run completion requires the structured plan and zero writes.