All skills
sanity-io avatar

/sanity-studio-upgrade

@e5c04f4 official
by Sanitysanity-io/agent-toolkit187 stars
30

Produces a tailored Sanity Studio upgrade plan by inspecting the repository's installed versions, config, and source, then reporting only the breaking changes that actually apply. Covers Studio v3 and later; v2 projects are identified and redirected, not planned. Use this skill whenever someone wants to upgrade, migrate, or modernize a Sanity Studio across one or more major versions from v3 onward, asks what will break if they bump the `sanity` package, asks why their Studio broke after an upgrade, or asks how far behind their Studio is. Triggers on "upgrade sanity studio", "migrate our studio to v6", "bump sanity", "what breaks if we upgrade", "our studio is on an old version", "sanity upgrade plan", "is our studio out of date", "we are several majors behind". DO NOT load for upgrading non-Sanity dependencies, for Content Lake `apiVersion` questions, for content or schema migrations that change documents, or for setting up a new Sanity project.

Use this Skill: https://skilld.dev/gh/sanity-io/agent-toolkit/sanity-studio-upgrade

This session only. Nothing lands on disk.

referencesdeprecations.md

≈642 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Cross-cutting deprecations

Not tied to a single boundary. Check these on any span.


1. Scheduled publishing, studioHost, and deploy hostnames

Not tied to a boundary, but worth checking on any span.

Scheduled publishing was deprecated in October 2025 and remains gated behind scheduledPublishing: {enabled: true}. If a project still uses it, migrating to Scheduled drafts or Content Releases is separate work and should be scoped separately rather than folded into a version upgrade.

studioHost naming collision. Two different things share this name, and conflating them causes unnecessary refactors:

  • studioHost and metadata.externalStudioHost as read fields on the project information API response are deprecated, because a project can now host multiple Studios and a single field cannot represent them all. There is currently no public replacement for listing studio deployments programmatically. If a project reads either field from the projects API, that genuinely needs attention.
  • studioHost as a write option in defineCliConfig, which tells sanity deploy which hostname to target, is a different surface. It is used throughout the hosting and deployment documentation, including the recommended pattern of configuring projectId, dataset, and studioHost via environment variables for building multiple Studios from one codebase. sanity undeploy also targets the host from CLI config.

Note that studioHost does not appear in the CLI configuration reference's property table while the deployment documentation uses it. That inconsistency is worth flagging to the reader as something to confirm, but it is not itself evidence that the CLI option is being removed. Describe the current documented state and do not speculate about future releases.

deployment.appId is not a replacement for studioHost. appId identifies an already-deployed Studio and exists to enable fine-grained auto-update version selection. The two are complementary, and appId provides little benefit while autoUpdates is false.

Deploying and hostname assignment. Hostname assignment happens through the CLI. A first sanity deploy prompts for a hostname interactively. sanity deploy --url <hostname> sets it non-interactively, --title names a newly created studio, and --dry-run reports what would be created without creating it, which is useful when rolling out across many deployments. Renaming, hiding from Dashboard, and removing a studio are available on the project's Studios tab in Sanity Manage.

Source: SKILL.md on GitHub

1 warning22d3 checks · Risk SAFE
  • Gen Agent Trust Hub22d

    This skill generates tailored Sanity Studio upgrade plans by inspecting repository files and querying official documentation and registry data. It incorporates strict safety guidelines, including read-only operation and live verification of version data. A low-severity finding for indirect prompt injection surface is noted because the skill processes untrusted local project content.

  • Socket22d

    No alerts

  • Snyk22d

    Risk: MEDIUM · 1 issue

Signed by skilld at e5c04f4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 3 weeks ago
Other metadata
compatibility
Requires network access to the npm registry and sanity.io docs for version and changelog lookups

README badge

README badge for sanity-io/agent-toolkit/sanity-studio-upgrade