dependency-upgrade-pr

$npx mdskill add Significant-Gravitas/skills-catalog/dependency-upgrade-pr

Use this after an upgrade plan has a reviewed target.

SKILL.md

.github/skills/dependency-upgrade-prView on GitHub ↗
---
name: "dependency-upgrade-pr"
description: "Draft a narrow dependency upgrade pull request with evidence, code changes, tests, risk notes, and rollback instructions."
triggers: ["upgrade PR", "dependency pull request", "draft update PR", "bump package", "security upgrade patch"]
version: "1"
---

# Dependency upgrade PR

Use this after an upgrade plan has a reviewed target.

## Keep the change narrow

Update the manifest and lockfile with the package manager. Make only the code
or configuration edits required by the verified migration notes. Do not mix
formatting, refactors, unrelated package bumps, or silent alert suppressions
into the change.

## Validate

Run the smallest relevant tests first, then the project checks required by its
contribution guide. Inspect the resolved dependency tree and built artifact.
For a security fix, rerun the scanner or version check that found it. Record
commands, results, and anything you could not run.

## Draft the pull request

State the old and new versions, reason, advisory or release-note sources,
behaviour changed, files changed, test evidence, known risk, rollout check, and
rollback. Mark it draft when approval or a check remains.

## Stop point

Never merge, deploy, bypass a failed check, or claim production is fixed. Hand
the draft and evidence to the named reviewer.

More from Significant-Gravitas/skills-catalog

SkillDescription
account-health-and-qbrsUse when a support account wobbles or a quarterly business review looms: read the health signals, run the success plan, and prep the review from evidence.
accounts-receivable-follow-upReview open receivables and draft factual, staged payment follow-ups without inventing status or contacting a customer.
ad-copy-variantsWrite ad variants that each test one idea, within platform limits and supported claims.
alex-getting-startedUse on the first conversation with Alex, or whenever their memory has no product preferences yet: learn what the user is building and who for, where specs, roadmap and numbers live, who decides dates and scope, and get them to a first real product deliverable.
alliance-co-commercializationUse when a strategic alliance needs joint selling governance: operating model, joint targeting, steering prep, and milestone accountability.
anika-getting-startedUse on the first conversation with Anika, or whenever their memory has no partnership preferences yet: learn which partners and alliances the user owns, what motion they run, and get one real partner read on screen in the same session.
assure-partner-led-deliveryUse when partners deliver client work in your name: own the in-flight book, run the weekly delivery review, and rescue engagements before clients feel it.
automate-finance-reportingUse to connect a number source, map an export into the finance ledger, or QA a sheet: the column mapping, the dedupe key, the load summary, and the checks that must pass before a read ships.
billing-refunds-and-exceptionsUse when money is on the table: verify the charge, check the policy, and stage a refund or exception draft that stops at the owner's yes.
board-and-investor-metrics-briefPrepare a concise board or investor metrics brief with definitions, sources, comparisons, drivers, risks, and decisions needed.