Update Packages

SkillDev tools

Lets your agent update workspace package dependencies while following the repo's pinned versions config.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Update Packages skill

About this capability

Update workspace packages while respecting the repo's pinned package list in .ncurc.cjs. Use when the user asks to update dependencies or refresh package versions.

What this skill tells your AI

The instructions your AI receives, as published by elie222/inbox-zero in .claude/skills/update-packages/SKILL.md and read by ahel’s review.

Use this workflow when updating dependencies in this repo.

Steps

  1. Check the pinned package list in .ncurc.cjs. Do not upgrade packages listed there.
  2. Keep the repo on Node 24. If you change Node runtime settings, update .nvmrc, engines.node, @types/node, Dockerfiles, and CI together.
  3. Update manifests across the workspace:
pnpm dlx npm-check-updates -u -ws
  1. Refresh the lockfile and install updated packages:
pnpm install
  1. Verify the update:
pnpm test
pnpm lint

Notes

  • npm-check-updates reads .ncurc.cjs, so the reject list is applied during the manifest update.
  • pnpm install may also bump the root packageManager field and regenerate pnpm-lock.yaml.
  • Do not run pnpm dev or pnpm build unless the user explicitly asks.
  • Keep @hookform/resolvers in the .ncurc.cjs reject list and pinned to 4.1.0 while apps/web remains on zod@3.25.76. The 5.x resolver line imports zod/v4/core, which has caused local Next.js/Turbopack resolution failures even though the app code still uses Zod 3.

Signals

GitHub stars
12k
Forks
2k
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
update-packages
Source
github.com/elie222/inbox-zero
Update Packages (update-packages): Skill · ahel