Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Upgrade all dependencies in an npm project to their latest versions.
.claude/skills/itsbencodes-upgrade-dependencies/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-13 | ✗→✓ | ▲ Improved | -14% | 0% |
| case-09 | ✗→✓ | ▲ Improved | -35% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -37% | 0% |
| case-17 | ✗→✓ | ▲ Improved | -29% | 0% |
| case-18 | ✗→✓ | ▲ Improved | -41% | 0% |
bashgit checkout main && git pull
bashgit checkout -b chore/upgrade-deps-$(date +%Y-%m-%d)
bashnpm outdated
npm outdated walks the workspace tree by default. The Wanted column is the highest match for the existing range; Latest is the absolute newest. Anything where Latest > Wanted is a major bump.
Group upgrades by risk so a breakage is easy to bisect. Commit each group separately.
bash npm update --workspaces --include-workspace-root
This respects the semver ranges already in package.json, so it only pulls in patches and minors.
npm-check-updates to rewrite the range, then reinstall:bash npx npm-check-updates -u --filter <pkg> npm install
For a workspace package, run ncu from inside that workspace directory or pass --packageFile packages/<name>/package.json. Read each package's CHANGELOG/release notes for breaking changes before bumping. Update call sites in the same commit.
Always verify with npm view <pkg> version that "latest" is what you got.
If package-lock.json still pins an old transitive after a direct bump, add an overrides entry in the root package.json. Use range-keyed overrides ("<pkg>@<major>": "<version>") when different majors of the same package coexist in the tree — a flat override forces every consumer onto the same version and routinely breaks packages that depend on the old API. Confirm with npm ls <pkg> that each major resolves where you expect.
Remove any overrides entries that are now redundant (the direct dep already carries a safe version).
Use the validate skill after every group; fix failures before moving on.
If a major bump breaks the build and the migration is non-trivial, roll back that specific upgrade (npm install <pkg>@<previous>), note it in the PR body under "Deferred", and keep moving. Do not commit a broken build.
Use the commit skill with title chore: upgrade dependencies and body:
## Upgraded
- <pkg>: <old> → <new>
## Deferred (breaking, needs follow-up)
- <pkg> <old> → <new>: <reason>| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-13 | fail→pass | 9,645 | 5,535 | -43% | 1 | 1 | 0% | 1,791 | 1,548 | -14% | 0 | 0 | — |
case-01 | fail→fail | 21,545 | 5,636 | -74% | 1 | 1 | 0% | 3,357 | 1,130 | -66% | 0 | 0 | — |
case-02 | fail→fail | 17,970 | 6,377 | -65% | 1 | 1 | 0% | 2,519 | 991 | -61% | 0 | 0 | — |
case-03 | fail→fail | 4,909 | 6,865 | +40% | 1 | 1 | 0% | 236 | 1,037 | +339% | 0 | 0 | — |
case-04 | pass→pass | 18,831 | 11,143 | -41% | 1 | 1 | 0% | 2,272 | 2,587 | +14% | 0 | 0 | — |
case-05 | pass→pass | 10,280 | 9,384 | -9% | 1 | 1 | 0% | 2,002 | 2,430 | +21% | 0 | 0 | — |
case-06 | pass→pass | 11,404 | 13,429 | +18% | 1 | 1 | 0% | 2,186 | 2,817 | +29% | 0 | 0 | — |
case-07 | pass→pass | 9,492 | 2,776 | -71% | 1 | 1 | 0% | 1,657 | 1,104 | -33% | 0 | 0 | — |
case-08 | pass→pass | 8,295 | 2,900 | -65% | 1 | 1 | 0% | 1,358 | 1,189 | -12% | 0 | 0 | — |
case-09 | fail→pass | 16,343 | 10,281 | -37% | 1 | 1 | 0% | 2,689 | 1,737 | -35% | 0 | 0 | — |
case-10 | pass→pass | 6,724 | 7,590 | +13% | 1 | 1 | 0% | 1,162 | 1,026 | -12% | 0 | 0 | — |
case-11 | pass→pass | 5,734 | 2,736 | -52% | 1 | 1 | 0% | 949 | 1,022 | +8% | 0 | 0 | — |
case-12 | fail→pass | 14,232 | 4,534 | -68% | 1 | 1 | 0% | 2,081 | 1,315 | -37% | 0 | 0 | — |
case-14 | pass→pass | 6,085 | 1,916 | -69% | 1 | 1 | 0% | 1,036 | 865 | -17% | 0 | 0 | — |
case-15 | pass→pass | 10,104 | 3,201 | -68% | 1 | 1 | 0% | 1,553 | 1,278 | -18% | 0 | 0 | — |
case-16 | pass→pass | 8,019 | 2,176 | -73% | 1 | 1 | 0% | 1,525 | 1,030 | -32% | 0 | 0 | — |
case-17 | fail→pass | 8,647 | 1,438 | -83% | 1 | 1 | 0% | 1,172 | 831 | -29% | 0 | 0 | — |
case-18 | fail→pass | 11,944 | 2,788 | -77% | 1 | 1 | 0% | 1,851 | 1,089 | -41% | 0 | 0 | — |
case-19 | pass→pass | 16,335 | 5,269 | -68% | 1 | 1 | 0% | 2,225 | 1,548 | -30% | 0 | 0 | — |
case-20 | fail→pass | 9,379 | 1,852 | -80% | 1 | 1 | 0% | 1,602 | 901 | -44% | 0 | 0 | — |
case-21 | pass→pass | 3,429 | 1,939 | -43% | 1 | 1 | 0% | 565 | 840 | +49% | 0 | 0 | — |
case-22 | pass→pass | 8,332 | 1,752 | -79% | 1 | 1 | 0% | 1,422 | 906 | -36% | 0 | 0 | — |
case-23 | fail→pass | 5,937 | 2,016 | -66% | 1 | 1 | 0% | 1,003 | 966 | -4% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted, and 20 counted toward the lift figure. The other 3 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +30 percentage points is the difference between those two pass rates over the 20 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.