{"enrichment":{"faq":[{"a":"dependency-upgrade automates the process of updating project dependencies while prioritizing security against supply chain threats. It integrates seamlessly with Claude Code CLI to manage package upgrades safely and efficiently, implementing staged rollout strategies, automated testing, and pre-installation auditing to prevent supply chain attacks during the upgrade process.","q":"How does dependency-upgrade help to upgrade npm dependencies safely?"},{"a":"dependency-upgrade employs multiple supply chain attack prevention techniques across all major package managers. It validates packages before installation through pre-install auditing tools, disables risky postinstall scripts by default, enforces lockfile validation in CI/CD pipelines, implements typosquatting protection, and integrates security scoring mechanisms to harden package manager security comprehensively.","q":"What methods does dependency-upgrade use to prevent supply chain attacks in package managers?"},{"a":"Yes, dependency-upgrade supports configuring automated dependency updates with built-in testing and cooldown periods. This allows teams to stagger updates across environments, validate changes through automated testing before production deployment, and maintain stability while ensuring security patches are applied systematically without overwhelming the system.","q":"Can dependency-upgrade configure a cooldown period for package updates?"},{"a":"dependency-upgrade enables teams to plan and execute staged major version upgrades by analyzing dependency trees, identifying breaking changes, and orchestrating rollouts across development, staging, and production environments. This approach minimizes disruption while ensuring thorough testing at each stage before advancing to the next phase.","q":"How does dependency-upgrade handle major version upgrade path planning?"},{"a":"dependency-upgrade hardens package manager security across all major tools by enforcing frozen lockfiles in CI/CD, validating npm provenance and 2FA publishing requirements, resolving peer dependency conflicts safely, and integrating with pre-install auditing solutions. It provides consistent security policies regardless of which package manager your project uses.","q":"What security hardening features does dependency-upgrade provide across pnpm, bun, yarn, and npm?"},{"a":"dependency-upgrade tracks bundle size impact after upgrades as part of its comprehensive validation process. By measuring size changes alongside automated testing and security auditing, it ensures that dependency updates don't introduce unexpected bloat while maintaining the security and stability improvements that upgrades provide.","q":"Does dependency-upgrade monitor bundle size impact after upgrades?"}],"shadow_tags":["supply-chain-hardening","version-gating","malware-detection","ci-cd-automation","vulnerability-remediation","package-provenance","rollback-strategies","cross-platform-pm","security-policies"],"summary_rewrite":"This skill automates the process of updating project dependencies while prioritizing security against supply chain threats. It integrates seamlessly with Claude Code CLI to manage package upgrades safely and efficiently."},"files":[{"bytes":18954,"path":"plugins/dependency-upgrade/skills/dependency-upgrade/SKILL.md","sha256":"efede82d93cb1c6a47f238836ce52a6c352a78ca6348e0bd558b762a9fbab7b8","url":"https://skillfed.io/files/secondsky/claude-skills/dependency-upgrade/66543d75/SKILL.md"}],"id":"secondsky/claude-skills/dependency-upgrade","links":{"html":"https://skillfed.io/secondsky/claude-skills/dependency-upgrade","md":"https://skillfed.io/secondsky/claude-skills/dependency-upgrade.md","repo":"https://github.com/secondsky/claude-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":29,"language":"TypeScript","last_updated":"2026-07-25","license":"MIT","name":"dependency-upgrade","publisher":"secondsky","stars":196},"relations":{"similar":[{"id":"secondsky/sap-skills/dependency-upgrade"},{"id":"secondsky/sap-skills/sap-dependency-security"},{"id":"Aradotso/security-skills/npm-security-best-practices"},{"id":"secondsky/claude-skills/bun-package-manager"},{"id":"vasilyu1983/AI-Agents-public/dev-dependency-management"},{"id":"curiositech/some_claude_skills/dependency-management"},{"id":"jamditis/claude-skills-journalism/supply-chain-hardening"},{"id":"Aradotso/security-skills/pypi-security-best-practices"},{"id":"grafana/skills/audit-and-reduce-dependencies"},{"id":"tartinerlabs/skills/deps"}]},"slug":{"owner":"secondsky","repo":"claude-skills","skill":"dependency-upgrade"},"version":"66543d75"}
