All skills
pulumi avatar

/package-usage

@49e2562 official
by pulumipulumi/agent-skills70 stars
6

Track which stacks across a Pulumi organization use a specific package and at what versions. Use for cross-stack audits, identifying outdated or unmaintained package versions across many stacks, finding affected stacks before publishing breaking changes to a component package, or planning coordinated upgrade rollouts. Do NOT use for upgrading a cloud provider package (pulumi-aws, pulumi-azure-native, pulumi-gcp, pulumi-kubernetes, etc.) in a single project — use skill `provider-upgrade` instead. Do NOT use for general infrastructure creation, resource provisioning, or how-to questions about a package.

Use this Skill: https://skilld.dev/gh/pulumi/agent-skills/package-usage

This session only. Nothing lands on disk.

SKILL.md

≈156 tokens always: the name and description. ≈531 when used: this file. ≈290 more on demand in 2 files.

API Reference

Query the Pulumi Cloud API with the pulumi api CLI subcommand. It authenticates with your existing Pulumi credentials and returns JSON.

Get the latest version of a package

pulumi api /api/registry/packages -F name={package_name} -F orgLogin={orgName}

Include orgLogin with the user's organization name. Omit -F name=... to list all packages visible to the organization (useful when the user has not named a specific package). The response contains a packages array. Each entry has a version field (the latest version), plus name, publisher, source, and packageStatus.

Get stack usage for a package

pulumi api /api/orgs/{orgName}/packages/usage -F packageName={package_name}

Replace {orgName} with the org name from context, PULUMI_ORG, or ask the user. packageName is required; query one package at a time.

Response fields:

  • packageName: The queried package
  • stacks: Array of {stackName, projectName, version, lastUpdate}
  • totalStacks: Total count

Workflow: Find outdated stacks

Use when the user wants to know which stacks are using an outdated version of a package.

  1. Get the latest version of the package
  2. Get stack usage for the package
  3. Compare each stack's version against the latest to identify outdated stacks
  4. Present results using the output format below

Output Format

Present results as a markdown table followed by a summary line:

| Project | Stack | Current Version | Latest Version | Status |
|---------|-------|-----------------|----------------|--------|
| my-app  | dev   | 6.40.0          | 6.52.0         | Outdated |
| my-app  | prod  | 6.52.0          | 6.52.0         | Up-to-date |

2 of 2 stacks checked. 1 outdated.

Out of scope: upgrading a specific stack

This skill identifies outdated stacks. It does not perform the upgrade itself. For actually bumping a package version in a project — editing package.json, requirements.txt, pyproject.toml, go.mod, or Pulumi.yaml, running pulumi preview, and reconciling the diff — hand off to the provider-upgrade skill.

Source: SKILL.md on GitHub

No alerts17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill is safe for use. It enables auditing of Pulumi package versions across an organization using the official Pulumi CLI. It interacts only with Pulumi's own infrastructure and does not perform any high-risk operations or data exfiltration.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 49e2562. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
  • pulumi
  • package-management
  • auditing
  • version-tracking
  • cross-stack
  • registry

README badge

README badge for pulumi/agent-skills/package-usage

Audits package versions across all stacks in a Pulumi organization, comparing each stack's version against the latest available version. Identifies outdated stacks and affected targets before publishing breaking changes to component packages or planning coordinated upgrades.

Generated from the current SKILL.md.

What's the difference between this skill and the provider-upgrade skill?
This skill audits package usage across multiple stacks in an organization and identifies which ones are outdated. The provider-upgrade skill handles the actual upgrade process (editing config files, running pulumi preview, reconciling diffs) for a single project.
Can I use this to upgrade cloud provider packages like pulumi-aws or pulumi-gcp?
No. This skill is for tracking usage of arbitrary packages across stacks. For upgrading Pulumi provider packages (pulumi-aws, pulumi-azure-native, pulumi-gcp, pulumi-kubernetes), use the provider-upgrade skill instead.
Does this skill actually perform the upgrade, or just report which stacks are outdated?
It only reports. This skill identifies outdated stacks and generates a comparison table. Upgrading a specific stack requires the provider-upgrade skill.
What information does this skill return about each stack?
For each stack using the package, it returns the stack name, project name, current version, and last update timestamp. It also fetches the latest available version to flag outdated entries.

Generated from the current SKILL.md. These answers refresh after source changes.