All skills
paulrberg avatar

/node-deps-bumper

@2d4f4a6
by Paul Bergpaulrberg/agent-skills94 stars
7

Use for dependency updates: bump npm/pnpm/yarn/bun packages, check outdated, or run taze.

Use this Skill: https://skilld.dev/gh/paulrberg/agent-skills/node-deps-bumper

This session only. Nothing lands on disk.

referencesconditional-workflows.md

≈890 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Conditional Workflows

Both sections below are gated: read only when the triggering condition in SKILL.md is met.

Minimum Release Age Mode

Use this mode for projects that configure a package-manager minimum-age policy.

Discover the effective project and user-level package-manager configuration. A configured age gate makes @latest a valid initial selector and ^x.y.z a valid retained manifest range: the installer filters out releases inside the cooldown. Do not exact-pin solely to impose the same freshness boundary; Bun still age-gates exact requests but they bypass its rapid-release stability check. The age gate is not a reproducibility mechanism; commit the lockfile and use frozen installs in deployment. If the deployment resolves dependencies without that lockfile, require the same effective age policy there or exact-pin for that workflow.

Taze calls this maturityPeriod:

  • --maturity-period [days] filters out package versions newer than the given number of days
  • --maturity-period-exclude <packages> excludes packages from that filter, when supported by the installed Taze version
# 7-day cooldown
taze major -r --maturity-period 7

For Bun minimumReleaseAge, convert seconds to whole days using a ceiling division. Example: 604800 seconds becomes --maturity-period 7. If the configured seconds are not a whole number of days, round up so Taze is not weaker than the package manager policy.

Taze v19.13.0+ auto-infers maturity periods from pnpm and Yarn workspace config, but not from Bun bunfig.toml. For Bun projects, pass --maturity-period explicitly.

For Bun lockfile projects, run-taze.sh uses Python 3.11+ through uv to parse the global .bunfig.toml under $XDG_CONFIG_HOME (or $HOME when unset), then overlay project [install] keys. Multiline exclusion arrays are supported; an explicit local 0 or empty array overrides the inherited value. See Bun configuration. Verify the installer actually enforces inherited age settings; if it ignores them, preserve the policy in project configuration before installing.

When the package manager config has an exclude list, pass matching Taze excludes if available:

taze major -r --maturity-period 7 --maturity-period-exclude react,webpack

run-taze.sh adds these flags itself for Bun lockfile projects and rejects extra options; Taze infers them for pnpm and Yarn. Append the same maturity flags only to direct Taze scan and write commands. After Taze writes manifests, run the project package manager install as usual; the package manager remains the final enforcement layer for direct and transitive resolution.

Update Bun Catalogs

When the root package.json contains catalog / catalogs at the top level or under workspaces, use scripts/update-bun-catalogs.py with the saved Taze plan and the selected packages present in catalogs. Skip this helper if that subset is empty. Preview before manifest writes; after the baseline passes, rerun the same command with --write, then perform the selected Taze write and regenerate the lockfile. Taze can update Bun catalogs natively, so running it first would invalidate the helper's saved plan.

The helper owns default/named catalog discovery, multiple occurrences, prefix preservation, stale-plan validation, and atomic replacement. The agent owns which upgrades are accepted and whether a major migration is compatible. Do not manually reproduce the catalog transition or weaken a helper failure.

Source: SKILL.md on GitHub

No alertstoday3 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    This skill is a utility for managing and bumping Node.js dependencies using Taze. It includes robust workflows for reviewing updates, handling Bun catalogs, and validating changes against the project's test suite. It accesses local configuration files to respect maturity policies but includes safeguards to prevent sensitive data leakage.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

Signed by skilld at 2d4f4a6. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 days ago
Modelsonnet
argument-hint
[--dry-run] [package ...] [repo-path ...]
effort
medium
model
sonnet

README badge

README badge for paulrberg/agent-skills/node-deps-bumper