Dependency Updater

softaworks/agent-toolkit/skills/dependency-updater

作者 softaworks3027f20f3181MIT2.5K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 個月前更新

Smart dependency management for any language. Auto-detects project type, applies safe updates automatically, prompts for major versions, diagnoses and fixes dependency issues.

AI 產生的概覽

自動辨識專案語言與套件管理器,安全更新相依套件並執行弱點稽核。

功能
此技能會掃描專案中的套件檔案(例如 package.json、requirements.txt、go.mod、Cargo.toml、Gemfile、pom.xml 或 .csproj),以判斷使用的語言與套件管理器。它會檢查過期的套件,自動套用次版本與修補版本更新,並在套用主版本更新前逐一詢問使用者。它也會執行各語言專屬的安全性稽核、診斷相依性衝突或損毀問題,最後執行安裝指令並回報結果。
適用情境
適用於需要將專案相依套件升級至最新版本、檢查過期套件,或解決相依性衝突與安裝錯誤的情況。也適合執行相依套件安全性稽核,並依嚴重程度處理發現的問題。
執行需求
需要對應的語言工具鏈與套件管理器(例如 npm、pip、Go、Cargo、Bundler、Maven 或 dotnet),以及選用的更新與稽核工具,如 taze、pip-review、pip-audit、safety、govulncheck、cargo audit 或 bundle audit。需要網路存取以取得套件中介資料與更新。技能附帶兩個可執行指令碼:scripts/check-tool.sh 與 scripts/run-taze.sh。

Dependency Updater

Smart dependency management for any language with automatic detection and safe updates.


Quick Start

update my dependencies

The skill auto-detects your project type and handles the rest.


Triggers

TriggerExample
Update dependencies"update dependencies", "update deps"
Check outdated"check for outdated packages"
Fix dependency issues"fix my dependency problems"
Security audit"audit dependencies for vulnerabilities"
Diagnose deps"diagnose dependency issues"

Supported Languages

LanguagePackage FileUpdate ToolAudit Tool
Node.jspackage.jsontazenpm audit
Pythonrequirements.txt, pyproject.tomlpip-reviewsafety, pip-audit
Gogo.modgo get -ugovulncheck
RustCargo.tomlcargo updatecargo audit
RubyGemfilebundle updatebundle audit
Javapom.xml, build.gradlemvn versions:*mvn dependency:*
.NET*.csprojdotnet outdateddotnet list package --vulnerable

Quick Reference

Update TypeVersion ChangeAction
FixedNo ^ or ~Skip (intentionally pinned)
PATCHx.y.z → x.y.ZAuto-apply
MINORx.y.z → x.Y.0Auto-apply
MAJORx.y.z → X.0.0Prompt user individually

Workflow

User Request    │    ▼┌─────────────────────────────────────────────────────┐│ Step 1: DETECT PROJECT TYPE                         ││ • Scan for package files (package.json, go.mod...) ││ • Identify package manager                          │├─────────────────────────────────────────────────────┤│ Step 2: CHECK PREREQUISITES                         ││ • Verify required tools are installed               ││ • Suggest installation if missing                   │├─────────────────────────────────────────────────────┤│ Step 3: SCAN FOR UPDATES                            ││ • Run language-specific outdated check              ││ • Categorize: MAJOR / MINOR / PATCH / Fixed         │├─────────────────────────────────────────────────────┤│ Step 4: AUTO-APPLY SAFE UPDATES                     ││ • Apply MINOR and PATCH automatically               ││ • Report what was updated                           │├─────────────────────────────────────────────────────┤│ Step 5: PROMPT FOR MAJOR UPDATES                    ││ • AskUserQuestion for each MAJOR update             ││ • Show current → new version                        │├─────────────────────────────────────────────────────┤│ Step 6: APPLY APPROVED MAJORS                       ││ • Update only approved packages                     │├─────────────────────────────────────────────────────┤│ Step 7: FINALIZE                                    ││ • Run install command                               ││ • Run security audit                                │└─────────────────────────────────────────────────────┘

Commands by Language

Node.js (npm/yarn/pnpm)

bash
# Check prerequisitesscripts/check-tool.sh taze "npm install -g taze"
# Scan for updatestaze
# Apply minor/patchtaze minor --write
# Apply specific majorstaze major --write --include pkg1,pkg2
# Monorepo supporttaze -r  # recursive
# Securitynpm auditnpm audit fix

Python

bash
# Check outdatedpip list --outdated
# Update all (careful!)pip-review --auto
# Update specificpip install --upgrade package-name
# Securitypip-auditsafety check

Go

bash
# Check outdatedgo list -m -u all
# Update allgo get -u ./...
# Tidy upgo mod tidy
# Securitygovulncheck ./...

Rust

bash
# Check outdatedcargo outdated
# Update within semvercargo update
# Securitycargo audit

Ruby

bash
# Check outdatedbundle outdated
# Update allbundle update
# Update specificbundle update --conservative gem-name
# Securitybundle audit

Java (Maven)

bash
# Check outdatedmvn versions:display-dependency-updates
# Update to latestmvn versions:use-latest-releases
# Securitymvn dependency:treemvn dependency-check:check

.NET

bash
# Check outdateddotnet list package --outdated
# Update specificdotnet add package PackageName
# Securitydotnet list package --vulnerable

Diagnosis Mode

When dependencies are broken, run diagnosis:

Common Issues & Fixes

IssueSymptomsFix
Version Conflict"Cannot resolve dependency tree"Clean install, use overrides/resolutions
Peer Dependency"Peer dependency not satisfied"Install required peer version
Security Vulnnpm audit shows issuesnpm audit fix or manual update
Unused DepsBloated bundleRun depcheck (Node) or equivalent
Duplicate DepsMultiple versions installedRun npm dedupe or equivalent

Emergency Fixes

bash
# Node.js - Nuclear resetrm -rf node_modules package-lock.jsonnpm cache clean --forcenpm install
# Python - Clean virtualenvrm -rf venvpython -m venv venvsource venv/bin/activatepip install -r requirements.txt
# Go - Reset modulesrm go.sumgo mod tidy

Security Audit

Run security checks for any project:

bash
# Node.jsnpm auditnpm audit --json | jq '.metadata.vulnerabilities'
# Pythonpip-auditsafety check
# Gogovulncheck ./...
# Rustcargo audit
# Rubybundle audit
# .NETdotnet list package --vulnerable

Severity Response

SeverityAction
CriticalFix immediately
HighFix within 24h
ModerateFix within 1 week
LowFix in next release

Anti-Patterns

AvoidWhyInstead
Update fixed versionsIntentionally pinnedSkip them
Auto-apply MAJORBreaking changesPrompt user
Batch MAJOR promptsLoses contextPrompt individually
Skip lock fileIrreproducible buildsAlways commit lock files
Ignore security alertsVulnerabilitiesAddress by severity

Verification Checklist

After updates:

  • Updates scanned without errors
  • MINOR/PATCH auto-applied
  • MAJOR updates prompted individually
  • Fixed versions untouched
  • Lock file updated
  • Install command ran
  • Security audit passed (or issues noted)

<details> <summary><strong>Deep Dive: Project Detection</strong></summary>

The skill auto-detects project type by scanning for package files:

File FoundLanguagePackage Manager
package.jsonNode.jsnpm/yarn/pnpm
requirements.txtPythonpip
pyproject.tomlPythonpip/poetry
PipfilePythonpipenv
go.modGogo modules
Cargo.tomlRustcargo
GemfileRubybundler
pom.xmlJavaMaven
build.gradleJava/KotlinGradle
*.csproj.NETdotnet

Detection order matters for monorepos:

  1. Check current directory first
  2. Then check for workspace/monorepo patterns
  3. Offer to run recursively if applicable
</details> <details> <summary><strong>Deep Dive: Node.js with taze</strong></summary>

Prerequisites

bash
# Install taze globally (recommended)npm install -g taze
# Or use npxnpx taze

Smart Update Flow

bash
# 1. Scan all updatestaze
# 2. Apply safe updates (minor + patch)taze minor --write
# 3. For each major, prompt user:#    "Update @types/node from ^20.0.0 to ^22.0.0?"#    If yes, add to approved list
# 4. Apply approved majorstaze major --write --include approved-pkg1,approved-pkg2
# 5. Installnpm install  # or pnpm install / yarn

Auto-Approve List

Some packages have frequent major bumps but are backward-compatible:

PackageReason
lucide-reactIcon library, majors are additive
@types/*Type definitions, usually safe
</details> <details> <summary><strong>Deep Dive: Version Strategies</strong></summary>

Semantic Versioning

MAJOR.MINOR.PATCH (e.g., 2.3.1)
MAJOR: Breaking changes - requires code changesMINOR: New features - backward compatiblePATCH: Bug fixes - backward compatible

Range Specifiers

SpecifierMeaningExample
^1.2.3Minor + Patch OK>=1.2.3 <2.0.0
~1.2.3Patch only>=1.2.3 <1.3.0
1.2.3Exact (fixed)Only 1.2.3
>=1.2.3At leastAny >=1.2.3
*AnyLatest (dangerous)

Recommended Strategy

json
{  "dependencies": {    "critical-lib": "1.2.3",      // Exact for critical    "stable-lib": "~1.2.3",       // Patch only for stable    "modern-lib": "^1.2.3"        // Minor OK for active  }}
</details> <details> <summary><strong>Deep Dive: Conflict Resolution</strong></summary>

Node.js Conflicts

Diagnosis:

bash
npm ls package-name      # See dependency treenpm explain package-name # Why installedyarn why package-name    # Yarn equivalent

Resolution with overrides:

json
// package.json{  "overrides": {    "lodash": "^4.18.0"  }}

Resolution with resolutions (Yarn):

json
{  "resolutions": {    "lodash": "^4.18.0"  }}

Python Conflicts

Diagnosis:

bash
pip checkpipdeptree -p package-name

Resolution:

bash
# Use virtual environmentpython -m venv venvsource venv/bin/activatepip install -r requirements.txt
# Or use constraintspip install -c constraints.txt -r requirements.txt
</details>

Script Reference

ScriptPurpose
scripts/check-tool.shVerify tool is installed
scripts/run-taze.shRun taze with proper flags

Related Tools

ToolLanguagePurpose
tazeNode.jsSmart dependency updates
npm-check-updatesNode.jsAlternative to taze
pip-reviewPythonInteractive pip updates
cargo-editRustCargo dependency management
bundler-auditRubySecurity auditing

來源與署名

來源:softaworks/agent-toolkit位於skills/dependency-updater提交3027f20

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架