upgrade-dependencies
Use when upgrading a JS/TS dependency or toolchain to a new/latest version (e.g. "upgrade TypeScript to the latest", "bump Vite to v7", major-version bumps), or when a build/typecheck/lint/test/CI goes red after a version bump and peer-dependency incompatibilities need resolving.
供给资产档案
编程与开发 Agent
代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。
场景
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
适配 Agent
Claude Code + CLI + Codex
适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。
安装
就绪
npx skills add AlemTuzlak/skills --skill upgrade-dependencies
维护状态
新鲜
距上次推送 2 天
风险
需审查
许可证不清晰
GitHub 质量
39
57/100 质量 · 68/100 信任
覆盖标签
审查说明
许可证不清晰 · Permission surface may require sandboxing
Agent 采用评分卡
一眼查看信任、审计与安装准备度
这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。
质量
有潜力有用的候选项,但采用前应与替代方案比较。
信任
仅限沙盒有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。
审计
需审查对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。
OpenAgentSkill 信任评分 v5
安装前需人工审查
仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。
Stars
39 个 GitHub Stars
仓库活跃度
39 个 Star,0 个 Fork
维护状态
距上次推送 2 天
许可证
未知
安装
npx skills add AlemTuzlak/skills --skill upgrade-dependencies
安装安全性
标准软件包或运行时安装路径
权限范围
shell or command execution, filesystem or document access
Agent 结果
暂未有 Agent 结果数据
文档
README/SKILL.md 上下文充分
风险摘要
生产前审查
- Repository license is unknown; no license file detected, which may create ambiguity about usage rights.
- 许可证不清晰
- Low GitHub adoption signal
- Quality score needs review
安装准备度
安装路径可用
- 安装路径可用
- 仓库证据可用
- 许可证不清晰
- 暂无 Agent 验证结果证据
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
适用任务
- GitHub automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
- Inspect repository metadata
适用 Agent
安装决策
- 命令
- npx skills add AlemTuzlak/skills --skill upgrade-dependencies
- 策略
- 审查
- 人工审查
- 是
信任与风险
- 信任
- 60/100
- 审计
- 72/100
- 风险级别
- 需审查
结果闭环
- 端点
- /api/agent/outcome
- 事件 ID
- resolve
- 结果
- 5
不适用场景
- 需要厂商支持 SLA 的团队
- production agents without a repository review
- Low GitHub adoption signal
- Repository license is unknown; no license file detected, which may create ambiguity about usage rights.
- 高风险权限提示:Shell 或命令执行
替代 Skill
Frontend Design
171.1K Stars
npx skills add anthropics/skills --skill frontend-design
替代 Skill
Taste Skill: Anti-Slop Frontend
79.4K Stars
npx skills add Leonxlnx/taste-skill --skill design-taste-frontend
替代 Skill
Canvas Design
171.1K Stars
npx skills add anthropics/skills --skill canvas-design
替代 Skill
Anthropic Brand Guidelines
171.1K Stars
npx skills add anthropics/skills --skill brand-guidelines
Agent 安全 v2
44/100 · 避免自动安装
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
高
Shell 或命令执行
Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。
中
网络访问
Skill 可能访问远程页面、API、仓库或外部服务。
中
文件系统访问
Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。
- 高风险权限提示:Shell 或命令执行
- 许可证不清晰
安装目标
在你的 Agent 工作流中安装此 Skill
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install alemtuzlak-upgrade-dependenciesAgent 解析计划
让 Agent 在安装前验证匹配度。
Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。
打开 JSON
/api/agent/resolve?task=Use%20upgrade-dependencies%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve 文本
/api/agent/resolve?task=Use%20upgrade-dependencies%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
安装交接
/api/skills/alemtuzlak-upgrade-dependencies/install
Agent 应检查
- 从 Resolve API 检查任务匹配与替代方案。
- 检查审计评分、信任评分和安全策略警告。
- 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。
复制提示词
Task: Use upgrade-dependencies in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20upgrade-dependencies%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alemtuzlak-upgrade-dependencies/install
Install command: npx skills add AlemTuzlak/skills --skill upgrade-dependencies
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 交接
把安装路径交给 Agent,而不是再给一个目录页。
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
安装交接
/api/skills/alemtuzlak-upgrade-dependencies/install
LLM 文本格式
/api/skills/alemtuzlak-upgrade-dependencies/install?format=text
寻找替代方案
/api/skills/search?q=upgrade-dependencies&limit=3
Agent 提示词
Use upgrade-dependencies for this task. Review https://www.openagentskill.com/api/skills/alemtuzlak-upgrade-dependencies/install, then install with: npx skills add AlemTuzlak/skills --skill upgrade-dependenciesRegistry 元数据
用于自动选择 Skill 的 Agent 可读档案。
本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。
Agent 决策面板
Fallback candidate for GitHub automation
先用此 Skill 做原型验证,并保留备选方案。
栈中角色
备选候选
主要匹配
GitHub automation
信任标签
先做原型验证
安装路径
命令已就绪
适用场景
- GitHub automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
证据
- 仓库近期活跃
- 已提供安装命令或 GitHub 仓库
- 57/100 质量档案
- 6 个 OpenAgentSkill 交互事件
先审查
- Low GitHub adoption signal
- Repository license is unknown; no license file detected, which may create ambiguity about usage rights.
实施路径
- 1在沙盒 Agent 中安装它,并端到端完成一次GitHub automation任务。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信任档案
仅限沙盒
有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。
GitHub 采用度
检查39 个 GitHub Stars
Star/Fork 活跃度
检查39 个 Star,0 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过距上次推送 2 天
许可证清晰度
检查未知
积极信号
- AI 审查已通过
- 安装路径可用
- 仓库证据可用
- 近期维护的仓库
- 安装命令未发现明显高风险模式
- 结果闭环已就绪,但需要首次真实 Agent 运行
安装前审查
- Repository license is unknown; no license file detected, which may create ambiguity about usage rights.
- 许可证不清晰
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- GitHub adoption: 39 GitHub stars
- Stars/forks activity: 39 stars, 0 forks; issue activity unavailable in current metadata
- License clarity: Unknown
- Permission surface: shell or command execution, filesystem or document access
- 暂未有真实 Agent 结果报告
- 无人值守安装前需要人工审查
建议操作
仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。
质量档案
有潜力 适用于 Agent 工作流的候选
有用的候选项,但采用前应与替代方案比较。
工作流匹配
在这些场景使用此 Skill
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Automate repeated work
Workflow automation
I need my agent to automate a repeated workflow across tools and files.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
工作流匹配
加入完整工作流
Design, build, test, and ship interfaces
Frontend and UI
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
替代方案短名单
安装前对比
可能适合该任务的相近 Skill。
Frontend Design
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
Taste Skill: Anti-Slop Frontend
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
Canvas Design
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
Anthropic Brand Guidelines
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
概览
--- name: upgrade-dependencies description: Use when upgrading a JS/TS dependency or toolchain to a new/latest version (e.g. "upgrade TypeScript to the latest", "bump Vite to v7", major-version bumps), or when a build/typecheck/lint/test/CI goes red after a version bump and peer-dependency incompatibilities need resolving. ---
# Upgrade Dependencies
Drive a dependency upgrade from "bump X to latest" all the way to green — without hacking around the errors it causes.
**Core principle: fix upward, never patch sideways.** When a bump breaks something, the fix is to upgrade the *thing that's incompatible* to a version that supports the target — not to suppress the error, downgrade the target, or add `// @ts-ignore`. If nothing upstream supports the target yet, that's a blocker you report, not a workaround you invent.
JS/TS ecosystems only (npm / pnpm / yarn / bun, including workspace monorepos and nx/turbo).
## The workflow
Work the phases in order. Scan the full impact (phase 2) before touching anything, and collect all breakage (phase 4) before fixing — otherwise you'll fix the same file three times and discover missed references halfway through.
### 1. Resolve the target version
- Absolute latest **stable** by default: `npm view <pkg> version` (dist-tag `latest`). Ignore existing semver ranges — the user asked to upgrade. - Use a prerelease (`next`/`rc`/`canary`) **only** if the user asked for it, or if it's the only version that unblocks a phase-5 blocker (and say so). - Detect the package manager from the lockfile: `pnpm-lock.yaml`→pnpm, `bun.lockb`→bun, `yarn.lock`→yarn, `package-lock.json`→npm. Never substitute a different runner. - Detect monorepo layout: root `workspaces`, `pnpm-workspace.yaml`, `nx.json`, `turbo.json`.
### 2. Scan the impact (read-only — before touching anything)
Do NOT bump yet. First, in one read-only pass, build the **impact map**: everything the upgrade will touch. This map drives every later phase.
- **Every reference to bump.** Grep the package name across all `package.json` — root and every workspace, `dependencies`/`devDependencies`/`peerDependencies` alike. Don't assume it lives in one place. - **Config/usage sites the version affects.** e.g. TypeScript → `tsconfig*.json` + everything compiled by `tsc`; Vite → `vite.config.*`; ESLint/Prettier → their config files. These are where a major bump's breaking changes land. - **Checks that exercise it** — don't guess. Read root+workspace `package.json` `scripts` (build, typecheck/`tsc`, lint, test…), `.github/workflows/*.{yml,yaml}` (what CI actually runs), and `nx.json`/`turbo.json` task graphs. Produce a concrete check list; include only checks the dep can affect. A TypeScript bump touches typecheck + build + anything running `tsc`; a Vite bump touches build + dev + test (if vitest); a linter bump touches lint. - **Third-party deps in the blast radius.** From the config/usage and peer requirements, note which other deps are likely to need their own upgrade to support the target (feeds phase 5).
Output of this phase: the list of files to bump, the check list to run, and the suspect deps — decided up front, not discovered mid-fix.
### 3. Bump everywhere
- Using the impact map, update **every** referencing `package.json` to the target version. - Reinstall to regenerate the lockfile with the repo's package manager.
### 4. Collect ALL breakage first
Run every mapped check **once** and capture full output per check. Now you know the total damage before touching code. Record which checks are red and the leading errors of each.
If everything's green — done. Report and stop.
### 5. Triage failures — upstream first
For each failing **third-party** dependency (the thing whose incompatibility is causing the error, e.g. Vite failing under TS 7):
1. Look up whether a newer release supports the target. Sources: `npm view <dep> peerDependencies`, `npm view <dep> versions`, the package's GitHub releases/CHANGELOG, and open issues/PRs referencing the target version. 2. **Compatible release exists** → bump that dep too (rescan + rebump, phases 2–3, for it), then continue. 3. **No compatible release exists** → **STOP that thread and report it as a blocker.** Include the evidence: the dep's latest version, its peer range, and the tracking issue/PR link if there is one. Do **not** downgrade the target, pin around it, or suppress the error to make the check pass.
Failures that are just your own code needing updates for the new version go straight to phase 6.
### 6. Fix, one check at a time, parallelized
Fix real code — new API usage, updated types, migrated config — never suppressions.
- Dispatch **one worktree-isolated subagent per independent check** (a build agent, a typecheck agent, a lint agent, a test agent). Give each agent: the target bump, its single check's command, and that check's captured errors. - Use worktrees so parallel agents don't collide on the same working tree (see `superpowers:using-git-worktrees` / your `blitz` skill). - Serialize instead when checks share the same files or when there are only one or two — parallel worktrees aren't free. - Each agent's exit bar: its check passes on real fixes.
### 7. Verify and report
- Merge the agents' branches, then re-run the **full** check set on the merged result. A fix that passed in isolation can fail once combined — loop phase 6/7 until the whole set is green. - Final report: - **Bumped:** target + any upstream deps you moved, with versions. - **Fixed:** which checks were red and what the real fix was. - **Blocked:** any deps held at their current version because upstream doesn't support the target yet, with evidence. These are the only things left un-upgraded, and the user decides what to do with them.
## Quick reference
| Step | Command / action | |------|------------------| | Latest stable | `npm view <pkg> version` | | All versions | `npm view <pkg> versions --json` | | Peer requirements | `npm view <dep> peerDependencies` | | Find every reference | grep the package name across all `package.json` | | What CI runs | read `.github/workflows/*` | | Reinstall | repo's package manager (lockfile decides) |
## Common mistakes
- **Bumping before scanning.** Editing `package.json` before the phase-2 impact pass means you find missed workspace references and affected configs mid-fix. Scan first, then bump. - **Fixing before mapping.** Jumping into errors before phase 4 means re-fixing files as later checks surface more of the same. Collect all breakage first. - **Patching sideways.** `@ts-ignore`, `eslint-disable`, downgrading the target, or pinning a dep to dodge the error. The failing dep's *upgrade* is the fix; absence of one is a blocker, not a license to suppress. - **Bumping in one file.** Missing workspace `package.json`s leaves a split-version install that "works" until it doesn't. Update every reference. - **Guessing the check list.** Running `test` when the dep only affects `build`, or missing a CI-only check. Read the scripts and workflows. - **Parallelizing overlapping fixes.** Two agents editing the same config in separate worktrees produces merge conflicts and lost work. Serialize when fixes touch shared files. - **Isolation-green ≠ merged-green.** Always re-run the full set after merging.
技术详情
- 版本
- 1.0.0
- 许可证
- Unknown
- 最近更新
- 2026年8月20日
- 发布时间
- 2026年8月20日
决策摘要
备选候选
仓库近期活跃
Agent 验证证据
Agent 验证证据
来自解析、审查、安装和一次小范围运行后的结果报告。
- 成功率
- —
- 近期失败
- —
- 结果
- 0
- 输出质量
- —
- 失败
- 0
- 不相关
- 0
- 安装次数
- 0
- 风险拦截
- 0
- 需要配置
- 0
- 生产环境
- 0
暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。
增长闭环
分享工具包
为 upgrade-dependencies 准备的场景化草稿,可手动发布到 X。
upgrade-dependencies: Use when upgrading a JS/TS dependency or toolchain to a new/latest version (e.g. "upgrade Typ... 39 stars https://www.openagentskill.com/skills/alemtuzlak-upgrade-dependencies?ref=x
可选:带安装命令的回复
Listing + install path for upgrade-dependencies: https://www.openagentskill.com/skills/alemtuzlak-upgrade-dependencies?ref=x Install: npx skills add AlemTuzlak/skills --skill upgrade-dependencies
收录来源
Registry 收录
此列表来自公开来源,维护者认领获批前不会标记为官方。
- 创作者
- AlemTuzlak
- 收录方
- OpenAgentSkill 社区索引
归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。
认领此 Skill所有者认领
认领此 Skill 页面
这条 Registry 收录 列表归属于 AlemTuzlak,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。
创作者外链工具包
将证据徽章加入你的 README
在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。
[](https://www.openagentskill.com/skills/alemtuzlak-upgrade-dependencies)
[](https://www.openagentskill.com/skills/alemtuzlak-upgrade-dependencies)
[](https://www.openagentskill.com/skills/alemtuzlak-upgrade-dependencies/audit)
[](https://www.openagentskill.com/skills/alemtuzlak-upgrade-dependencies)作者
AlemTuzlak
@alemtuzlak
平台适配
健康信号
- GitHub Stars
- 39
- 质量评分
- 34/100
- 最近 GitHub 推送
- 2026年8月20日
- 框架提示
- 未知
- OpenAgentSkill 浏览量
- 6
- 复制安装命令
- 0
- 跳转点击
- 0
社区信号
告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。
信任与安全
仅限沙盒
- GitHub 采用度39 个 GitHub Stars检查
- Star/Fork 活跃度39 个 Star,0 个 Fork; 当前元数据中没有议题活跃度信息检查
- 近期维护距上次推送 2 天通过
- 许可证清晰度未知检查
- README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
- 依赖与运行时风险network or browser surface通过
相关 Skill
Frontend Design
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
171.1K StarsTaste Skill: Anti-Slop Frontend
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
79.4K StarsCanvas Design
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
171.1K StarsAnthropic Brand Guidelines
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
171.1K Stars