Real Skill packageSource verifiedClawHub registry

upgrade-deps

Upgrade project dependencies safely — inventories current→target versions from the actual manifest/lockfile, reads the real changelog/release notes for every major bump (a breaking-change claim without a changelog citation is a hypothesis), greps the codebase for each breaking API before declaring it safe, upgrades one major at a time with tests+build quoted green between batches, and reports a per-package table of what changed and what evidence backs "safe". Use this skill whenever the user says "upgrade dependen…

Identity and source

Publisher attributionDennis Rongoregistry owner unverified by skillvetai
Functional categorySoftware Developmentautomatically inferred · 61% rule confidence
Package forminstruction bundle2 recorded files
Canonical sourceClawHub registryclawhub:dennisrongo:upgrade-deps
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 8/16/2026.claude/skills/upgrade-deps

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 8/16/2026.agents/skills/upgrade-deps

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 8/16/2026skills/upgrade-deps

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @dennisrongo/upgrade-deps
clawhub inspect @dennisrongo/upgrade-deps --version 1.0.0

Security evidence

SkillVetAI static result: no findings detected

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
2 / 2 inspected as text
Checked
8/16/2026, 9:38:28 PM
Scanner
0.1.3
Policy
1.0.3
2 inferred permission indicators
  • network access — automatically inferred
  • filesystem write — automatically inferred
1 dependency and API indicators
  • api: clawhub.ai
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
8/16/2026, 9:02:30 PM
Release binding
Matches this record
  • vt: clean
  • skillspector: clean
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:60cc28c436dbd07fd5a44ce25a202cff33b6056fb8b0f574e319ce5567c0cf4e
Show up to 2 recorded paths
  • skill-card.md
  • SKILL.md

Source changelog

Initial release of upgrade-deps skill. - Enables safe, evidence-based dependency upgrades for multiple ecosystems by reading real changelogs and searching for breaking APIs in the codebase. - Inventories outdated packages using the appropriate ecosystem tool, and distinguishes between patch/minor (batched) and major (one at a time) upgrades. - For major upgrades, reads changelogs for breaking changes, greps the repo for affected APIs, and explicitly names runtime risks and untested changes. - Runs full test builds between each upgrade batch, reporting results and only declaring upgrades safe if all checks pass. - Handles lockfile and peer dependency updates per ecosystem best practices. - Produces a per-package report table highlighting what changed, what was verified, and any blocked, held-back, or risky upgrades. - Covers a broad set of use cases from routine updates to security-drive…