dep-update
vndee/engineering-skills/.claude/skills/dep-update/SKILL.md
Use when updating dependencies, running security audits, or managing tech debt in Go, Python, or React projects
Skill3 starsChanged 7 months ago
What's in it
- Dependency Updates & Security
- Overview
- Go Update Workflow
- Python Update Workflow
- Bun/React Update Workflow
- Safe Update Process
- Update Categories
- Tech Debt Identification
- Chains
--- name: dep-update description: Use when updating dependencies, running security audits, or managing tech debt in Go, Python, or React projects --- # Dependency Updates & Security ## Overview Safe dependency update workflows for Go, Python (uv), and Bun. Branch per update, test after each. **Core principle:** One category at a time. Full test suite after each update. Never batch blindly. ## Go Update Workflow ```bash # 1. Check for updates go list -m -u all # 2. Update dependencies go get -u ./... # all deps go get -u package@v1.2 # specific # 3. Clean up go mod tidy # 4. Security audit govulncheck ./... # 5. Test go test ./... -race -count=1 ``` ## Python Update Workflow ```bash # 1. Check for updates uv pip list --outdated # 2. Update lock file uv lock --upgrade # all deps uv lock --upgrade-package pkg # specific # 3. Sync environment uv sync # 4. Type check (catches breaking API changes) mypy src/ # 5. Lint ruff check . # 6. Security audit pip-audit # 7. Test pytest ``` ## Bun/React Update Workflow ```bash # 1. Check for updates bun outdated # 2. Update bun update # all bun update package # specific # 3. Audit bun audit # or npm audit # 4. Test bun test bun run build # verify build still works ``` ## Safe Update Process 1. Create feature branch: `git checkout -b chore/dep-updates` 2. Update one category at a time (e.g., test deps, then framework, then DB) 3. Commit after each category with passing tests 4. Full test + type-check + lint after each commit 5. PR with summary of what changed ## Update Categories | Category | Risk | Update frequency | |----------|------|-----------------| | Security patches | Critical | Immediately | | Bug fixes (patch) | Low | Weekly | | Minor versions | Medium | Monthly | | Major versions | High | Quarterly (plan migration) | ## Tech Debt Identification Look for: - Deprecated API usage in dependency changelogs - Outdated patterns (pre-generics Go, pre-2.0 SQLAlchemy) - Unused dependencies (`go mod tidy`, `depcheck`) - Pinned versions with known vulnerabilities ## Chains - **REQUIRED:** Invoke `superpowers:finishing-a-development-branch` when done - **REQUIRED:** Update CLAUDE.md if major dependencies changed (`claude-md`)
More agent context in vndee/engineering-skills
36 other files this repository gives its agents.
Skill
- adr.claude/skills/adr/SKILL.md
- analytics.claude/skills/analytics/SKILL.md
- api-contract.claude/skills/api-contract/SKILL.md
- api-design.claude/skills/api-design/SKILL.md
- ci-pipeline.claude/skills/ci-pipeline/SKILL.md
- claude-md.claude/skills/claude-md/SKILL.md
- code-quality.claude/skills/code-quality/SKILL.md
- data-model.claude/skills/data-model/SKILL.md
- db-migrate.claude/skills/db-migrate/SKILL.md
- debug.claude/skills/debug/SKILL.md
- deploy.claude/skills/deploy/SKILL.md
- disk-cleanup.claude/skills/disk-cleanup/SKILL.md
- docker-build.claude/skills/docker-build/SKILL.md
- eng-lead.claude/skills/eng-lead/SKILL.md
- event-driven.claude/skills/event-driven/SKILL.md
- fullstack-healthcheck.claude/skills/fullstack-healthcheck/SKILL.md
- go-feature.claude/skills/go-feature/SKILL.md
- go-integration-test.claude/skills/go-integration-test/SKILL.md
- go-refactor.claude/skills/go-refactor/SKILL.md
- go-scaffold.claude/skills/go-scaffold/SKILL.md
- incident-response.claude/skills/incident-response/SKILL.md
- interactive-clarify.claude/skills/interactive-clarify/SKILL.md
- observability.claude/skills/observability/SKILL.md
- onboarding.claude/skills/onboarding/SKILL.md
- product-spec.claude/skills/product-spec/SKILL.md
- py-feature.claude/skills/py-feature/SKILL.md
- py-integration-test.claude/skills/py-integration-test/SKILL.md
- py-migrate.claude/skills/py-migrate/SKILL.md
- py-refactor.claude/skills/py-refactor/SKILL.md
- py-scaffold.claude/skills/py-scaffold/SKILL.md
- react-feature.claude/skills/react-feature/SKILL.md
- react-refactor.claude/skills/react-refactor/SKILL.md
- react-scaffold.claude/skills/react-scaffold/SKILL.md
- review-code.claude/skills/review-code/SKILL.md
- security.claude/skills/security/SKILL.md
- system-design.claude/skills/system-design/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
Reports can't be read right now.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

