Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Smart dependency management for any language. Auto-detects project type, applies safe updates automatically, prompts for major versions, diagnoses and fixes dependency issues.
.claude/skills/davila7-dependency-updater/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-14 | ✗→✓ | ▲ Improved | 87% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 152% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 250% | 0% |
| case-02 | ✓→✗ | ▼ Worse | 84% | 0% |
| case-06 | ✓→✓ | = Same ✓ | 139% | 0% |
Smart dependency management for any language with automatic detection and safe updates.
update my dependenciesThe skill auto-detects your project type and handles the rest.
| Trigger | Example | |---------|---------| | Update dependencies | "update dependencies", "update deps" | | Check outdated | "check for outdated packages" | | Fix dependency issues | "fix my dependency problems" | | Security audit | "audit dependencies for vulnerabilities" | | Diagnose deps | "diagnose dependency issues" |
| Language | Package File | Update Tool | Audit Tool | |----------|--------------|-------------|------------| | Node.js | package.json | taze | npm audit | | Python | requirements.txt, pyproject.toml | pip-review | safety, pip-audit | | Go | go.mod | go get -u | govulncheck | | Rust | Cargo.toml | cargo update | cargo audit | | Ruby | Gemfile | bundle update | bundle audit | | Java | pom.xml, build.gradle | mvn versions:* | mvn dependency:* | | .NET | .csproj | dotnet outdated | dotnet list package --vulnerable |
| Update Type | Version Change | Action | |-------------|----------------|--------| | Fixed | No ^ or ~ | Skip (intentionally pinned) | | PATCH | x.y.z → x.y.Z | Auto-apply | | MINOR | x.y.z → x.Y.0 | Auto-apply | | MAJOR | x.y.z → X.0.0 | Prompt user individually |
User Request
│
▼
┌─────────────────────────────────────────────────────┐
│ Step 1: DETECT PROJECT TYPE │
│ • Scan for package files (package.json, go.mod...) │
│ • Identify package manager │
├─────────────────────────────────────────────────────┤
│ Step 2: CHECK PREREQUISITES │
│ • Verify required tools are installed │
│ • Suggest installation if missing │
├─────────────────────────────────────────────────────┤
│ Step 3: SCAN FOR UPDATES │
│ • Run language-specific outdated check │
│ • Categorize: MAJOR / MINOR / PATCH / Fixed │
├─────────────────────────────────────────────────────┤
│ Step 4: AUTO-APPLY SAFE UPDATES │
│ • Apply MINOR and PATCH automatically │
│ • Report what was updated │
├─────────────────────────────────────────────────────┤
│ Step 5: PROMPT FOR MAJOR UPDATES │
│ • AskUserQuestion for each MAJOR update │
│ • Show current → new version │
├─────────────────────────────────────────────────────┤
│ Step 6: APPLY APPROVED MAJORS │
│ • Update only approved packages │
├─────────────────────────────────────────────────────┤
│ Step 7: FINALIZE │
│ • Run install command │
│ • Run security audit │
└─────────────────────────────────────────────────────┘bash# Check prerequisites scripts/check-tool.sh taze "npm install -g taze" # Scan for updates taze # Apply minor/patch taze minor --write # Apply specific majors taze major --write --include pkg1,pkg2 # Monorepo support taze -r # recursive # Security npm audit npm audit fix
bash# Check outdated pip list --outdated # Update all (careful!) pip-review --auto # Update specific pip install --upgrade package-name # Security pip-audit safety check
bash# Check outdated go list -m -u all # Update all go get -u ./... # Tidy up go mod tidy # Security govulncheck ./...
bash# Check outdated cargo outdated # Update within semver cargo update # Security cargo audit
bash# Check outdated bundle outdated # Update all bundle update # Update specific bundle update --conservative gem-name # Security bundle audit
bash# Check outdated mvn versions:display-dependency-updates # Update to latest mvn versions:use-latest-releases # Security mvn dependency:tree mvn dependency-check:check
bash# Check outdated dotnet list package --outdated # Update specific dotnet add package PackageName # Security dotnet list package --vulnerable
When dependencies are broken, run diagnosis:
| Issue | Symptoms | Fix | |-------|----------|-----| | Version Conflict | "Cannot resolve dependency tree" | Clean install, use overrides/resolutions | | Peer Dependency | "Peer dependency not satisfied" | Install required peer version | | Security Vuln | npm audit shows issues | npm audit fix or manual update | | Unused Deps | Bloated bundle | Run depcheck (Node) or equivalent | | Duplicate Deps | Multiple versions installed | Run npm dedupe or equivalent |
bash# Node.js - Nuclear reset rm -rf node_modules package-lock.json npm cache clean --force npm install # Python - Clean virtualenv rm -rf venv python -m venv venv source venv/bin/activate pip install -r requirements.txt # Go - Reset modules rm go.sum go mod tidy
Run security checks for any project:
bash# Node.js npm audit npm audit --json | jq '.metadata.vulnerabilities' # Python pip-audit safety check # Go govulncheck ./... # Rust cargo audit # Ruby bundle audit # .NET dotnet list package --vulnerable
| Severity | Action | |----------|--------| | Critical | Fix immediately | | High | Fix within 24h | | Moderate | Fix within 1 week | | Low | Fix in next release |
| Avoid | Why | Instead | |-------|-----|---------| | Update fixed versions | Intentionally pinned | Skip them | | Auto-apply MAJOR | Breaking changes | Prompt user | | Batch MAJOR prompts | Loses context | Prompt individually | | Skip lock file | Irreproducible builds | Always commit lock files | | Ignore security alerts | Vulnerabilities | Address by severity |
After updates:
<details> <summary><strong>Deep Dive: Project Detection</strong></summary>
The skill auto-detects project type by scanning for package files:
| File Found | Language | Package Manager | |------------|----------|-----------------| | package.json | Node.js | npm/yarn/pnpm | | requirements.txt | Python | pip | | pyproject.toml | Python | pip/poetry | | Pipfile | Python | pipenv | | go.mod | Go | go modules | | Cargo.toml | Rust | cargo | | Gemfile | Ruby | bundler | | pom.xml | Java | Maven | | build.gradle | Java/Kotlin | Gradle | | *.csproj | .NET | dotnet |
Detection order matters for monorepos:
</details>
<details> <summary><strong>Deep Dive: Node.js with taze</strong></summary>
bash# Install taze globally (recommended) npm install -g taze # Or use npx npx taze
bash# 1. Scan all updates taze # 2. Apply safe updates (minor + patch) taze minor --write # 3. For each major, prompt user: # "Update @types/node from ^20.0.0 to ^22.0.0?" # If yes, add to approved list # 4. Apply approved majors taze major --write --include approved-pkg1,approved-pkg2 # 5. Install npm install # or pnpm install / yarn
Some packages have frequent major bumps but are backward-compatible:
| Package | Reason | |---------|--------| | lucide-react | Icon library, majors are additive | | @types/* | Type definitions, usually safe |
</details>
<details> <summary><strong>Deep Dive: Version Strategies</strong></summary>
MAJOR.MINOR.PATCH (e.g., 2.3.1)
MAJOR: Breaking changes - requires code changes
MINOR: New features - backward compatible
PATCH: Bug fixes - backward compatible| Specifier | Meaning | Example | |-----------|---------|---------| | ^1.2.3 | Minor + Patch OK | >=1.2.3 <2.0.0 | | ~1.2.3 | Patch only | >=1.2.3 <1.3.0 | | 1.2.3 | Exact (fixed) | Only 1.2.3 | | >=1.2.3 | At least | Any >=1.2.3 | | * | Any | Latest (dangerous) |
json{ "dependencies": { "critical-lib": "1.2.3", // Exact for critical "stable-lib": "~1.2.3", // Patch only for stable "modern-lib": "^1.2.3" // Minor OK for active } }
</details>
<details> <summary><strong>Deep Dive: Conflict Resolution</strong></summary>
Diagnosis:
bashnpm ls package-name # See dependency tree npm explain package-name # Why installed yarn why package-name # Yarn equivalent
Resolution with overrides:
json// package.json { "overrides": { "lodash": "^4.18.0" } }
Resolution with resolutions (Yarn):
json{ "resolutions": { "lodash": "^4.18.0" } }
Diagnosis:
bashpip check pipdeptree -p package-name
Resolution:
bash# Use virtual environment python -m venv venv source venv/bin/activate pip install -r requirements.txt # Or use constraints pip install -c constraints.txt -r requirements.txt
</details>
| Script | Purpose | |--------|---------| | scripts/check-tool.sh | Verify tool is installed | | scripts/run-taze.sh | Run taze with proper flags |
| Tool | Language | Purpose | |------|----------|---------| | taze | Node.js | Smart dependency updates | | npm-check-updates | Node.js | Alternative to taze | | pip-review | Python | Interactive pip updates | | cargo-edit | Rust | Cargo dependency management | | bundler-audit | Ruby | Security auditing |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-06 | pass→pass | 12,236 | 11,813 | -3% | 1 | 1 | 0% | 2,042 | 4,880 | +139% | 0 | 0 | — |
case-05 | pass→pass | 10,685 | 5,890 | -45% | 1 | 1 | 0% | 1,535 | 3,675 | +139% | 0 | 0 | — |
case-01 | fail→fail | 4,405 | 8,087 | +84% | 1 | 1 | 0% | 484 | 3,262 | +574% | 0 | 0 | — |
case-02 | pass→fail | 19,248 | 5,504 | -71% | 1 | 1 | 0% | 1,746 | 3,204 | +84% | 0 | 0 | — |
case-03 | pass→pass | 9,838 | 5,846 | -41% | 1 | 1 | 0% | 1,765 | 3,868 | +119% | 0 | 0 | — |
case-04 | pass→pass | 11,276 | 5,653 | -50% | 1 | 1 | 0% | 1,920 | 3,874 | +102% | 0 | 0 | — |
case-07 | pass→pass | 7,289 | 2,754 | -62% | 1 | 1 | 0% | 1,186 | 3,337 | +181% | 0 | 0 | — |
case-08 | pass→pass | 6,955 | 4,822 | -31% | 1 | 1 | 0% | 1,268 | 3,647 | +188% | 0 | 0 | — |
case-09 | pass→pass | 11,265 | 5,613 | -50% | 1 | 1 | 0% | 1,890 | 3,875 | +105% | 0 | 0 | — |
case-10 | pass→pass | 13,870 | 5,621 | -59% | 1 | 1 | 0% | 2,306 | 3,870 | +68% | 0 | 0 | — |
case-11 | pass→pass | 11,553 | 9,424 | -18% | 1 | 1 | 0% | 1,791 | 3,660 | +104% | 0 | 0 | — |
case-12 | pass→pass | 8,461 | 6,285 | -26% | 1 | 1 | 0% | 1,445 | 3,569 | +147% | 0 | 0 | — |
case-13 | fail→fail | 12,414 | 7,865 | -37% | 1 | 1 | 0% | 2,027 | 3,972 | +96% | 0 | 0 | — |
case-14 | fail→pass | 17,565 | 14,610 | -17% | 1 | 1 | 0% | 2,874 | 5,378 | +87% | 0 | 0 | — |
case-15 | fail→pass | 10,676 | 7,824 | -27% | 1 | 1 | 0% | 1,633 | 4,117 | +152% | 0 | 0 | — |
case-16 | pass→pass | 8,832 | 5,332 | -40% | 1 | 1 | 0% | 1,547 | 3,751 | +142% | 0 | 0 | — |
case-17 | pass→pass | 12,934 | 4,914 | -62% | 1 | 1 | 0% | 2,110 | 3,667 | +74% | 0 | 0 | — |
case-18 | pass→pass | 10,801 | 6,836 | -37% | 1 | 1 | 0% | 2,014 | 4,178 | +107% | 0 | 0 | — |
case-19 | fail→pass | 7,111 | 2,432 | -66% | 1 | 1 | 0% | 943 | 3,301 | +250% | 0 | 0 | — |
case-20 | pass→pass | 8,962 | 14,456 | +61% | 1 | 1 | 0% | 1,861 | 5,599 | +201% | 0 | 0 | — |
case-21 | pass→pass | 5,591 | 4,462 | -20% | 1 | 1 | 0% | 1,051 | 3,649 | +247% | 0 | 0 | — |
case-22 | fail→fail | 3,221 | 8,451 | +162% | 1 | 1 | 0% | 321 | 4,314 | +1244% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +9 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.