Skip to content

feat(claude-code): upgrading-dependencies skill; sync skill 1.2.0 - #136

Open
gatezh wants to merge 1 commit into
masterfrom
claude-code/upgrading-dependencies-skill
Open

gatezh wants to merge 1 commit into
masterfrom
claude-code/upgrading-dependencies-skill

Conversation

@gatezh

@gatezh gatezh commented Sep 9, 2026

Copy link
Copy Markdown
Owner

What

Adds a bundled upgrading-dependencies skill to the claude-code template — SKILL.md plus scripts/changelog-slice.mjs — and bumps devcontainer-upstream-sync to 1.2.0 with manifest rows for the two new files.

Why

Dependency upgrades are the recurring maintenance task where an agent most reliably does the wrong thing: it schedules a major that two peers forbid, reads changelogs "later", writes ranges instead of exact pins, and defers majors by reflex. Written TDD-style against a baseline planning run that did all four; with the skill present the same scenario holds the blocked family at the highest allowed line, still bumps the blocker's own version, pins exactly, and isolates auth and tool bumps.

Changes

  • claude-code/.claude/skills/upgrading-dependencies/SKILL.md — constraints before versions, changelog slices, regression search, exact pins in blast-radius groups, deprecation notices as scope, a report table.
  • claude-code/.claude/skills/upgrading-dependencies/scripts/changelog-slice.mjs — slices a raw CHANGELOG.md or GitHub Releases (by tag prefix) to the upgraded range and prints only breaking/deprecation lines; tells you which prefixes it saw when nothing matches, since an empty slice is usually a wrong prefix, not "no changes".
  • claude-code/.claude/skills/devcontainer-upstream-sync/SKILL.md — 1.2.0: manifest rows for the two files above, so downstream projects pick them up through the normal audit loop.

Notes

Adopted downstream first (a Bun + mise monorepo on Cloudflare Workers); the skill is generic to Bun/npm workspaces with .mise.toml pins and reads the project's CLAUDE.md for its pin style and gate costs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant