Agent Skillsstella/stella › update-deps

update-deps

GitHub

跨生态(Bun/Python/Cargo/Docker/GitHub Actions)依赖管理技能,负责盘点、评估、更新及验证第三方依赖,处理版本冲突与供应链风险。

.agents/skills/update-deps/SKILL.md stella/stella

Trigger Scenarios

用户要求更新或升级项目依赖包 需要检查并报告过期的第三方库

Install

npx skills add stella/stella --skill update-deps -g -y
More Options

Non-standard path

npx skills add https://github.com/stella/stella/tree/main/.agents/skills/update-deps -g -y

Use without installing

npx skills use stella/stella@update-deps

指定 Agent (Claude Code)

npx skills add stella/stella --skill update-deps -a claude-code -g -y

安装 repo 全部 skill

npx skills add stella/stella --all -g -y

预览 repo 内 skill

npx skills add stella/stella --list

SKILL.md

Frontmatter
{
    "name": "update-deps",
    "description": "Inventory, assess, update, and validate third-party dependencies across Bun, Python\/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk."
}

Update Dependencies

Review or update the dependency scope requested by the user. Discover the repository's actual manifests and source-of-truth files before running ecosystem commands; do not assume they live at the root.

1. Resolve Scope and Sources of Truth

Inspect repository instructions, workspace manifests, lockfiles, dependency catalogs or resolutions, automated update configuration, and open dependency PRs when relevant. Common sources include:

  • package.json, workspace manifests, bun.lock, and bunfig.toml
  • every relevant pyproject.toml, uv.lock, and Python constraints file
  • every relevant Cargo.toml and its Cargo.lock
  • Dockerfile* and Compose YAML
  • .github/workflows/* and dependency-update configuration

Default to an inventory and recommendation unless the user asks to apply updates. When applying a broad sweep, split it into coherent, independently validated batches. Give every major and heavy minor its own validated batch and commit. A heavy minor is a minor whose official release notes require migration or whose application requires source, configuration, or schema changes beyond dependency manifests and lockfiles.

"Separate" means its own batch and commit, not its own pull request and not omitted. An applied sweep covers every applicable update within the requested scope and each dependency's intended registry channel. Keep stable dependencies on stable releases. Include prerelease updates only within an explicitly selected prerelease channel. The only reason to leave a version behind is a mechanical block: a release still inside the repository's release-age quarantine, a peer or engine constraint that cannot be satisfied, or an upstream break with no migration path. Report each block with its reason. Upgrade size, review burden, and "risky major" are not blocks.

For every major and heavy minor, read the official release notes for capabilities worth adopting, not only for breakage. Report the relevant migration details and capabilities adopted or identified with the version moves.

2. Inventory the Full Requested Surface

Run Bun inventory from the workspace root:

bun outdated --filter="*"

For each relevant Rust manifest, inspect the full dependency graph:

cargo outdated --manifest-path <path/to/Cargo.toml>

If cargo-outdated is unavailable, preview compatible lockfile updates with:

cargo update --manifest-path <path/to/Cargo.toml> --dry-run

This dry run is an incomplete inventory: it cannot surface releases outside the manifest's current version requirements. Supplement it with registry-aware cargo info or cargo search checks for every direct dependency in scope, and report the limitation. Do not default to --root-deps-only when cargo-outdated is available: transitive changes can carry the material risk.

For each uv-managed Python project, inspect direct and transitive packages:

uv tree --project <path> --locked --outdated

Also compare every direct dependency's declared constraint with authoritative PyPI metadata. uv tree --outdated can hide a newer release when the current constraint excludes it, so it is not a complete major-version inventory by itself. Keep accelerator packages and their container runtime in one compatibility batch: verify the Python wheel's CUDA/ROCm requirements against the selected base image and exercise a native-library import or linkage smoke test.

Inventory container references across Dockerfiles and Compose files:

rg -n '^\s*(FROM|image:)\s+' \
  --glob 'Dockerfile*' \
  --glob '*compose*.yml' \
  --glob '*compose*.yaml' \
  --glob '!node_modules/**'

Resolve current tags and digests from authoritative registry metadata. Inspect GitHub Actions when requested or when workflow files are in scope.

Flag exact prerelease pins and non-stable channels separately. Package-manager "latest" output can miss a newer alpha, beta, rc, next, canary, or dev release on the intended channel. Query registry tags and compare the deliberate channel.

3. Assess Upgrade and Supply-Chain Risk

Treat patch, minor, major, pre-1.0 minor, and prerelease moves according to their actual compatibility risk. Read official release notes, migration guides, engine or peer requirements, image notes, and package metadata. Search current usage for deprecated APIs, compatibility shims, and workarounds the release could remove.

Before adopting a fresh or high-risk release, inspect cheap signals first:

  • release age relative to repository quarantine policy
  • publisher, maintainer, repository, or homepage changes
  • missing tags or unexplained release notes
  • new lifecycle scripts, native binaries, or bundled blobs
  • image provenance, supported platforms, and digest movement

Use package tarball or image-layer inspection only when those signals are odd, the dependency is high risk, or the user requested a deeper audit. Prefer official sources and registry metadata over third-party summaries.

4. Apply Deliberate Updates

Update the real source of truth: a shared catalog or resolution before duplicating versions across workspaces. Preserve the intended prerelease channel explicitly; do not use a flag that silently replaces it with stable latest.

For Bun versions already allowed by the manifest, update only the planned packages:

bun update <package>

When a shared catalog owns the version, edit that catalog and run bun install instead of creating workspace drift. Use bun update <package> --latest only when intentionally changing the declared dependency range. Resolve and preserve an intended prerelease version or channel explicitly.

For Rust, use targeted lockfile updates:

cargo update --manifest-path <path/to/Cargo.toml> -p <crate>

Edit the manifest only when the declared requirement must change. Do not run bare cargo update for an ordinary batch; a full-graph update must be an explicit, reviewed choice.

For uv, update only the planned packages and review the resulting lockfile:

uv lock --project <path> --upgrade-package <package>
uv sync --project <path> --frozen

Edit pyproject.toml when intentionally widening or changing a direct dependency constraint. Do not run an unscoped full Python upgrade unless the batch explicitly covers the full Python graph.

Pin GitHub Actions to commit SHAs and container images to immutable digests when that is repository policy. Review every manifest and lockfile delta for unexpected transitive additions, replacements, features, scripts, or platform changes.

Prefer removal over passive growth: delete obsolete shims, polyfills, or duplicate packages when the upgrade makes them unnecessary and the validation surface remains focused.

5. Validate and Report

Run the smallest affected checks first, then the repository's canonical verification for the touched surface. Use each Rust command with its actual manifest path, for example:

cargo check --manifest-path <path/to/Cargo.toml>
cargo test --manifest-path <path/to/Cargo.toml>

Use each Python command against its actual project and locked environment, for example:

uv lock --project <path> --check
uv run --project <path> --locked <lint-or-test-command>

For native or GPU packages, also build the production image and run the repository's import/linkage smoke test so a resolver-green but ABI-incompatible update cannot land.

Run the repository's dependency or security audit command when it defines one, for example bun run security:audit, and report its result. Do not substitute a generic command for repository policy when no such audit is configured.

Verify generated artifacts when a dependency affects them. If applying multiple batches, commit each only after its validation passes so rollback remains clear.

Report the full inventory, current and target versions, risk classification, official migration evidence, concrete adoption opportunities, supply-chain assessment, applied batches, checks run, and deferred or blocked work.

Version History

  • dd81665 Current 2026-08-16 07:09

    从仅支持 Bun/Cargo/Docker 扩展至覆盖 Python/uv 和 GitHub Actions;新增对重型 Minor 版本迁移细节的分析及更严格的隔离提交策略。

  • 85792bd 2026-07-24 16:12

Same Skill Collection

.agents/skills/click-around/SKILL.md
.agents/skills/conventions-ai/SKILL.md
.agents/skills/conventions-db/SKILL.md
.agents/skills/conventions-i18n/SKILL.md
.agents/skills/conventions-ingestion/SKILL.md
.agents/skills/conventions-perf/SKILL.md
.agents/skills/conventions-scale/SKILL.md
.agents/skills/conventions-security/SKILL.md
.agents/skills/conventions-use-effect/SKILL.md
.agents/skills/conventions-ux/SKILL.md
.agents/skills/dev/SKILL.md
.agents/skills/finish-pr/SKILL.md
.agents/skills/new-handler/SKILL.md
.agents/skills/open-pr/SKILL.md
.agents/skills/plan/SKILL.md
.agents/skills/product-deep-think/SKILL.md
.agents/skills/product-think/SKILL.md
.agents/skills/rabbit-round/SKILL.md
.agents/skills/regression-hunt/SKILL.md
.agents/skills/security-audit/SKILL.md
.ai/local-skills/click-around/SKILL.md
.ai/local-skills/conventions-ai/SKILL.md
.ai/local-skills/conventions-db/SKILL.md
.ai/local-skills/conventions-i18n/SKILL.md
.ai/local-skills/conventions-ingestion/SKILL.md
.ai/local-skills/conventions-perf/SKILL.md
.ai/local-skills/conventions-scale/SKILL.md
.ai/local-skills/conventions-security/SKILL.md
.ai/local-skills/conventions-use-effect/SKILL.md
.ai/local-skills/conventions-ux/SKILL.md
.ai/local-skills/dev/SKILL.md
.ai/local-skills/new-handler/SKILL.md
.ai/local-skills/open-pr/SKILL.md
.ai/local-skills/plan/SKILL.md
.ai/local-skills/product-deep-think/SKILL.md
.ai/local-skills/rabbit-round/SKILL.md
.ai/local-skills/security-audit/SKILL.md
.ai/local-skills/update-deps/SKILL.md
packages/cli/skills/stella-cli/SKILL.md
packages/skills/blueprints/answer-from-sources/SKILL.md
packages/skills/blueprints/blank/SKILL.md
packages/skills/blueprints/check-against-rules/SKILL.md
packages/skills/blueprints/intake-to-draft/SKILL.md
.agents/skills/conventions-testing/SKILL.md
.ai/local-skills/conventions-testing/SKILL.md

Metadata

Files
0
Version
dd81665
Hash
3f5ae35e
Indexed
2026-07-24 16:12

inicio - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-16 23:39
浙ICP备14020137号-1 $mapa de visitantes$