Weekly dependency updates
Every week, an AI agent audits outdated and vulnerable dependencies, applies the safe updates on a branch, runs the tests and opens a pull request.
Dependency bots open one pull request per package and leave you to find out which ones break the build. This workflow works like a careful teammate instead: it audits everything first, applies only the updates within the scope you chose, runs your tests, and opens one pull request that explains what changed and what was left out.
How it works
- Audit: the agent detects the package managers of the repository and lists outdated and vulnerable dependencies, with the size of each jump and the known advisories.
- Update: on a new branch, it applies the updates within scope (patch only, or patch and minor), runs the install, the build and the tests, reverts any update that breaks them, and opens a pull request describing each change. Major versions are listed for a human to plan, never applied.
What you need
- An agent connected to the repository's machine, with the toolchain of the project (Node, .NET, Python…) and the GitHub CLI installed.
- A
GITHUB_TOKENworkspace secret allowed to push a branch and open pull requests.
Steps
1. Audit dependencies
Audit the dependencies of the git repository in the current directory. Do not modify any file in this step. 1. Detect the package managers from the repository files (package.json and lock files, *.csproj / Directory.Packages.props, pyproject.toml / requirements*.txt, Cargo.toml, go.mod…), ignoring vendored and generated directories. 2. For each ecosystem, list outdated dependencies with the ecosystem's tool (`npm outdated`, `dotnet list package --outdated`, `pip list --outdated`, `cargo outdated`…) and known vulnerabilities (`npm audit`, `dotnet list package --vulnerable`, `pip-audit`…), when available. 3. Write the audit in Markdown: one table per ecosystem with package, current, wanted (same major), latest, jump (patch / minor / major) and advisories. Then the list of updates within the "{{inputs.scope}}" scope, vulnerable ones first. Complete the step with `--value in_scope=<number of updates within scope>`.2. Apply safe updates
Apply the {{steps.audit-dependencies.outputs.in_scope}} dependency updates within the "{{inputs.scope}}" scope listed in the audit from the previous step, then open a pull request. If there are none, write one line saying so and complete the step. 1. Check that the GitHub CLI works (`gh auth status`) and that the working tree is clean; otherwise fail the step with the reason. 2. Create a branch from the default branch: `deps/weekly-<YYYY-MM-DD>`. 3. Apply the updates with the ecosystem's tools, keeping lock files consistent. Never change a major version. 4. Run the install, the build and the tests the repository documents (README, CLAUDE.md, CI configuration). If an update breaks them, revert that update alone and note why. 5. Commit, push the branch and open a pull request with `gh pr create`: the title "Weekly dependency updates (<date>)", and a body listing each update (from → to, advisories fixed), the updates reverted and why, and the major versions left for a human to plan. 6. Write a summary with the pull request URL. Complete the step with `--value pr_url=<url>`.
Secrets
GITHUB_TOKEN: A GitHub token allowed to push branches and open pull requests on the repository (fine-grained "Contents" and "Pull requests" read and write).
Suggested schedule: Tuesdays at 6:00
FAQ
Will it merge the pull request?
No. It opens the pull request and stops; your usual review and CI apply.
Which ecosystems are supported?
Any whose tools run on the agent's machine (npm, pnpm, yarn, NuGet, pip, Poetry, Cargo, Go modules…). The agent detects them from the repository files.