absolute-upgrade — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited absolute-upgrade (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Start your first response with the ⬆️ emoji.
Bring dependencies current — safely, in risk-ranked waves, with tests green after each. Not a blind npm update: outdated and vulnerable deps are grouped by blast radius (patch/minor → safe wave; major/breaking → gated, one at a time, changelog-read), applied incrementally, and verified against the project's own test suite.
Runs the shared engine in `references/health-engine.md` — read it for the DETECT → SCAN → TRIAGE → FIX → VERIFY → REPORT loop and the safety contract. This file covers only what's specific to dependency upgrades.
npm outdated / Dependabot backlog without 40 separate PRs.Not for: adding a new dependency (that's a work/feature decision), or auditing vulnerabilities specifically → use `/absolute audit` (it triages CVEs; upgrade moves versions).
Per ecosystem, list outdated deps with current → wanted → latest and the jump type:
| Ecosystem | Detect outdated | Lockfile / manifest |
|---|---|---|
| npm | npm outdated --json | package-lock.json |
| pnpm | pnpm outdated --format json | pnpm-lock.yaml |
| yarn | yarn outdated --json | yarn.lock |
| Python (pip) | pip list --outdated --format=json | requirements*.txt |
| Python (poetry/uv) | poetry show --outdated / uv pip list --outdated | pyproject.toml + lock |
| Go | go list -u -m -json all | go.mod / go.sum |
Also flag: deps with known deprecations, duplicate/multiple versions of the same package, and direct vs transitive (only direct deps are upgrade targets; transitives follow).
Group the upgrade plan into waves by semver jump — safest first:
| Wave | Jump | Default |
|---|---|---|
| 1 | patch (x.y.Z) | batch together, fix now |
| 2 | minor (x.Y.z) | batch by package family, fix now |
| 3 | major (X.y.z) / pre-1.0 minor | one at a time, gated — read the changelog/migration guide first, list breaking changes |
For every major bump: locate breaking changes (CHANGELOG, release notes, codemod if the package ships one), inventory call sites that touch the changed API, and state the migration before applying. Peer-dependency conflicts get resolved in the same wave as their driver.
install is not a passing upgrade).
build breaks. Use the package's codemod where one exists.
keep the green waves. Never --force / --legacy-peer-deps to mask a real conflict.
lockfile ships untested transitive versions. Always regenerate.
which change broke it. Majors are always solo.
npm install succeeding proves nothing — run tests.dependency tree to dodge it silently.
back here for the version moves.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.