Dependency Update (Freshness)
SkillAI & modelsBump outdated Hex deps — inventory, snapshot changelogs, update, fix
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Dependency Update (Freshness) skill
What this skill tells your AI
The instructions your AI receives, as published by oliver-kriska/claude-elixir-phoenix in targets/pi/skills/phx-deps-update/SKILL.md and read by ahel’s review.
Inventory → update → fix breaks → grouped PRs. This is the only MUTATING
deps skill: it edits mix.exs, mix.lock, and source. Security scanning
stays in /skill:phx-deps-audit; the vet ledger stays in /skill:phx-deps-vet.
Usage
/skill:phx-deps-update # inventory + interactive scope pick
/skill:phx-deps-update --scope patch # bundle all patch bumps, one PR
/skill:phx-deps-update --pkg phoenix_live_view # one package (+ coupled group)
/skill:phx-deps-update --dry-run # inventory only, no changes
Iron Laws
- NEVER cross a major version without an explicit
mix.exsedit —mix deps.updatestays within requirements. Edit the constraint first; addoverride: trueonly whenmix hex.outdated <pkg>shows a transitive consumer blocking. One major per PR - ALWAYS snapshot the changelog delta BEFORE updating — capture
deps/<pkg>/CHANGELOG.md, then delta viamix hex.package diff. Never update blind - NEVER claim an update is safe without verification — run
/skill:phx-verify(compile --warnings-as-errors + test). "Compiles" ≠ "works" - ALWAYS move coupled packages together — Phoenix core, Ecto, Ash,
Oban, telemetry families update in the SAME step/commit (see
references/coupled-groups.md) - NEVER commit a partial bump —
mix.lock+mix.exsedits + (for Phoenix-family)assets/package-lock.jsonin ONE commit - HAND OFF security to
/skill:phx-deps-audit— run it on the lock diff before any PR; don't reimplement audit rules hex.outdatedexit 1 is normal — it means "deps are outdated", not failure. Capture with|| true
Workflow
Phase 0: Discover
Read mix.exs: deps list, umbrella (apps_path:), git/path deps, private
orgs (organization:/repo: in tuples), Phoenix/Ash presence. Create
scratch dir .claude/deps-update/{YYYY-MM-DD}/.
Phase 1: Inventory
mix hex.outdated --all || true — parse the text table (no JSON exists;
see references/update-mechanics.md). Classify each
row patch/minor/major by semver delta; Update not possible = blocked
major (mix.exs constraint). Write inventory.md to scratch. Render
grouped table: Patch / Minor / Major / Blocked / Git-deps (manual).
--dry-run stops here.
Phase 2: Scope (AskUserQuestion)
Present groups with counts and risk. Default recommendation: "Patches (N)
— low risk, bundle into one PR". --scope/--pkg flags skip the prompt.
When ≥2 members of a coupled group are outdated, force them into one step
even under a narrower scope.
Phase 3: Per-Package Update Loop
For each selected package, in coupled-group order:
- Snapshot
deps/<pkg>/CHANGELOG.md→scratch/before/ - Update — patch/minor:
mix deps.update <pkg> [coupled...]; major: editmix.exsconstraint (+override: trueif needed), thenmix deps.update <pkg> git diff mix.lock→ the REAL{pkg, old, new}set (hex.outdated says what could change; the lock diff says what did)- Changelog delta:
mix hex.package diff <pkg> <old>..<new>— keep the CHANGELOG hunk. Empty →gh api repos/{o}/{r}/releasesfallback → compare-URL note (seereferences/changelog-sources.md) - Write
scratch/{pkg}-{old}-{new}.md - Phoenix-family in the diff +
assets/package.jsonexists →npm install --prefix assets, stageassets/package-lock.jsonwith the same commit
Phase 4: Verify
Run /skill:phx-verify. On failure → Phase 5; else Phase 6.
Phase 5: Breaking-Change Fixes
Read the changelog deltas for "breaking"/"removed"/"deprecated" + the compile/test errors. Fix source (apply the sibling-file check). Re-verify.
Phase 6: Security Handoff
Run /skill:phx-deps-audit on the working mix.lock diff (its Mode B default).
BLOCK findings → surface and offer /skill:phx-deps-vet <pkg> <ver> for
accepted risks. Never skip this before a PR.
Phase 7: Group, Commit, PR
Apply the splitting strategy (references/pr-strategy.md):
patches bundled, minors by area, majors solo, coupled groups always
together. PR bodies cite the changelog excerpt, the
https://diff.hex.pm/diff/<pkg>/<old>..<new> link, verification result,
and the deps-audit risk band. Stage lock + mix.exs + package-lock together.
Integration
/skill:phx-deps-update (mutating) → /skill:phx-deps-audit (security, Mode B)
│ │ BLOCK → /skill:phx-deps-vet (ledger)
└→ /skill:phx-verify (gate) → grouped commits / PRs
References
references/update-mechanics.md— hex.outdated parsing, update vs unlock+get, majors, lock-diffreferences/changelog-sources.md— hex.package diff, gh fallbacks, private orgsreferences/coupled-groups.md— must-move-together groups + edge casesreferences/pr-strategy.md— grouping rules, area buckets, PR template, scratch layout
Signals
- GitHub stars
- 543
- Forks
- 38
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
phx-deps-update- Source
- github.com/oliver-kriska/claude-elixir-phoenix