Install
$ agentstack add skill-paulrberg-dot-agents-bump-deps ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Bump Dependencies
Use Taze to build one structured update plan, apply compatible ranged updates, and make major-version decisions as a batch.
Workflow
- Resolve the skill directory and run the helper from the target repository:
``sh bash /scripts/run-taze.sh --plan [--include package-a,package-b] ``
The JSON plan classifies every discovered update as apply, review-major, review, or skip-fixed. The helper detects monorepos, includes locked versions during scans, and mirrors Bun minimum-release-age settings. If the repository uses package-manager age gates or Bun catalogs, read [references/conditional-workflows.md](references/conditional-workflows.md) for that active branch only.
- If
--dry-runwas requested, present the plan and counts, then stop without changing manifests or lockfiles.
- Select every ranged minor/patch update marked
apply. Never auto-approve a major package by name. Present all
review-major and unknown updates in one decision batch with current version, target version, package role when discoverable, and relevant migration/release notes. Apply only the majors the user selects.
- If nothing is selected, report the no-op and stop. Otherwise write all selected updates in one command:
``sh bash /scripts/run-taze.sh --write --include package-a,package-b ``
- Update matching root Bun catalog entries when present, preserving their existing range prefixes. Then run
niso the
repository's package manager updates its lockfile.
- Inspect the manifest and lockfile diff. Run the narrowest package-manager or repository checks that exercise updated
dependencies, with extra attention to approved major migrations.
Invariants
- Fixed versions and non-semver protocols remain unchanged unless the user explicitly asks otherwise.
- Package arguments constrain both scan and write phases.
- The same maturity-period policy applies to scan and write.
- Do not infer compatibility from SemVer alone when repository evidence, peer ranges, or release notes indicate
otherwise.
Completion requires a reviewed plan, one manifest write for the selected set, a regenerated lockfile, and validation evidence; dry-run completion requires the structured plan and zero writes.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: PaulRBerg
- Source: PaulRBerg/dot-agents
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.