phx-deps-update
Bump outdated Hex deps — inventory, snapshot changelogs, update, fix
Install / Use
npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-updateInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of phx-deps-update
phx-deps-update scores 82/100 on our quality scale, 972nd of 1,120 Security skills we index.
Its SKILL.md is 5.0 KB long, well organised into 14 sections with 2 code examples: a solid amount of guidance for an agent.
It has 560 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 3 days ago, so phx-deps-update is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
phx-deps-update compared with similar skills
All 4 of these similar skills score higher than phx-deps-update; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| phx-deps-update (this skill)by oliver-kriska | 82 | 560 | 3d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
Frequently asked questions
- How do I install phx-deps-update?
- Run
npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-update. The install tabs above show the steps for each supported agent. - Which AI agents does phx-deps-update work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is phx-deps-update safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is phx-deps-update still maintained?
- The repository was last updated 3 days ago, so phx-deps-update is actively maintained.
Skill content
View source on GitHubname: phx-deps-update description: Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo). Use to upgrade/bump Elixir dependencies or when versions fall behind. NOT for deps.get failures (phx-investigate).
Dependency Update (Freshness)
Inventory → update → fix breaks → grouped PRs. This is the only MUTATING
deps skill: it edits mix.exs, mix.lock, and source. Security scanning
stays in phx-deps-audit; the vet ledger stays in phx-deps-vet.
Usage
phx-deps-update # inventory + interactive scope pick
phx-deps-update --scope patch # bundle all patch bumps, one PR
phx-deps-update --pkg phoenix_live_view # one package (+ coupled group)
phx-deps-update --dry-run # inventory only, no changes
Iron Laws
- NEVER cross a major version without an explicit
mix.exsedit —mix deps.updatestays within requirements. Edit the constraint first; addoverride: trueonly whenmix hex.outdated <pkg>shows a transitive consumer blocking. One major per PR - ALWAYS snapshot the changelog delta BEFORE updating — capture
deps/<pkg>/CHANGELOG.md, then delta viamix hex.package diff. Never update blind - NEVER claim an update is safe without verification — run
phx-verify(compile --warnings-as-errors + test). "Compiles" ≠ "works" - ALWAYS move coupled packages together — Phoenix core, Ecto, Ash,
Oban, telemetry families update in the SAME step/commit (see
references/coupled-groups.md) - NEVER commit a partial bump —
mix.lock+mix.exsedits + (for Phoenix-family)assets/package-lock.jsonin ONE commit - HAND OFF security to
phx-deps-audit— run it on the lock diff before any PR; don't reimplement audit rules hex.outdatedexit 1 is normal — it means "deps are outdated", not failure. Capture with|| true
Workflow
Phase 0: Discover
Read mix.exs: deps list, umbrella (apps_path:), git/path deps, private
orgs (organization:/repo: in tuples), Phoenix/Ash presence. Create
scratch dir .claude/deps-update/{YYYY-MM-DD}/.
Phase 1: Inventory
mix hex.outdated --all || true — parse the text table (no JSON exists;
see references/update-mechanics.md). Classify each
row patch/minor/major by semver delta; Update not possible = blocked
major (mix.exs constraint). Write inventory.md to scratch. Render
grouped table: Patch / Minor / Major / Blocked / Git-deps (manual).
--dry-run stops here.
Phase 2: Scope (AskUserQuestion)
Present groups with counts and risk. Default recommendation: "Patches (N)
— low risk, bundle into one PR". --scope/--pkg flags skip the prompt.
When ≥2 members of a coupled group are outdated, force them into one step
even under a narrower scope.
Phase 3: Per-Package Update Loop
For each selected package, in coupled-group order:
- Snapshot
deps/<pkg>/CHANGELOG.md→scratch/before/ - Update — patch/minor:
mix deps.update <pkg> [coupled...]; major: editmix.exsconstraint (+override: trueif needed), thenmix deps.update <pkg> git diff mix.lock→ the REAL{pkg, old, new}set (hex.outdated says what could change; the lock diff says what did)- Changelog delta:
mix hex.package diff <pkg> <old>..<new>— keep the CHANGELOG hunk. Empty →gh api repos/{o}/{r}/releasesfallback → compare-URL note (seereferences/changelog-sources.md) - Write
scratch/{pkg}-{old}-{new}.md - Phoenix-family in the diff +
assets/package.jsonexists →npm install --prefix assets, stageassets/package-lock.jsonwith the same commit
Phase 4: Verify
Run phx-verify. On failure → Phase 5; else Phase 6.
Phase 5: Breaking-Change Fixes
Read the changelog deltas for "breaking"/"removed"/"deprecated" + the compile/test errors. Fix source (apply the sibling-file check). Re-verify.
Phase 6: Security Handoff
Run phx-deps-audit on the working mix.lock diff (its Mode B default).
BLOCK findings → surface and offer phx-deps-vet <pkg> <ver> for
accepted risks. Never skip this before a PR.
Phase 7: Group, Commit, PR
Apply the splitting strategy (references/pr-strategy.md):
patches bundled, minors by area, majors solo, coupled groups always
together. PR bodies cite the changelog excerpt, the
https://diff.hex.pm/diff/<pkg>/<old>..<new> link, verification result,
and the deps-audit risk band. Stage lock + mix.exs + package-lock together.
Integration
phx-deps-update (mutating) → phx-deps-audit (security, Mode B)
│ │ BLOCK → phx-deps-vet (ledger)
└→ phx-verify (gate) → grouped commits / PRs
References
references/update-mechanics.md— hex.outdated parsing, update vs unlock+get, majors, lock-diffreferences/changelog-sources.md— hex.package diff, gh fallbacks, private orgsreferences/coupled-groups.md— must-move-together groups + edge casesreferences/pr-strategy.md— grouping rules, area buckets, PR template, scratch layout
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
