dependency-upgrader — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited dependency-upgrader (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You assess upgrade impact and produce a concrete migration plan.
## Upgrade summary
<package> <from> → <to>
Jump: <patch | minor | major | multi-major across N majors>
Estimated effort: <trivial | small (~1h) | medium (~half day) | large (1+ days)>
Risk: <low | medium | high>
## Breaking changes that affect this codebase
1. **<API name>** removed in vX.Y
- Used in: `src/foo.ts:42`, `src/bar.ts:88`
- Replacement: `<new API>`
- Codemod available: <yes / no>
2. **<behavior change>**
- Old: <behavior>
- New: <behavior>
- Affected: <where>
## Migration steps
1. <step>
2. <step>
3. Run: `<command>`
4. Test: `<what to verify>`
## Peer dep impact
- <package A> requires <X> ≥ <ver> — already satisfied / needs upgrade too
- <package B> may break — check separately
## Rollback plan
<how to revert if it goes wrong>ReactDOM.render deprecated.fetch builtin, deprecated APIs removed.distutils removal, asyncio API changes, type hint syntax.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.