Upgrade notes
SkillDocs & knowledgeRead the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the `whatsnew` MCP server's `upgrade_notes` tool. Use WHENEVER any dependency version changes in this repository, a bump, downgrade, add or swap in `gradle/libs.versions.toml`, `gradle/wrapper/gradle-wrapper.properties`, a plugin or `buildscript` version, a GitHub Actions `uses:` ref, or a CI image tag, and whenever asked "is it safe to upgrade X", "what changed in X since Y", or to review a Renovate/Dependabot-style bump. Run it BEFORE editing the version, not after the build breaks.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Upgrade notes skill
What this skill tells your AI
The instructions your AI receives, as published by getknit/knit in .agents/skills/upgrade-notes/SKILL.md and read by ahel’s review.
Every version change in this repo gets the vendor's own notes read first. The whatsnew MCP server
(https://whatsnew.fyi/mcp, declared in .mcp.json, no auth) returns every tracked release between two
versions with the breaking, deprecation, migration and security sections verbatim, including breaking
changes that shipped in a minor or a patch.
This skill tells you what to read before a bump. .agents/context/toolchain.md still decides whether the
bump is allowed (minCompileSdk, the Kotlin/KSP lockstep, stable-only). Read both.
When the tool is missing
If no whatsnew tools are loaded, the server is not approved in this session. Tell the user once
(Claude Code: /mcp, approve whatsnew) and carry on with the upgrade by reading the vendor's release
notes directly. The skill is advisory; never block a bump on it.
Steps
-
List what is moving. For each dependency, take
fromfrom what is pinned now (the catalog entry, orapp/gradle.lockfile/settings-gradle.lockfilefor a transitive one) andtofrom the target version. Use exact versions, never ranges. A catalog[versions]key that several libraries share (lifecycle,cameraX,room3) is one call, not one per artifact. -
Call
upgrade_notes, up to 20 dependencies per call. The tool has no Maven registry: theregistryfield takes only npm, pypi, crates and rubygems, so leave it out and letrepositorymake the match.name: the Maven coordinategroup:artifact, the plugin id, or the action'sowner/repo.repository: the library's GitHub repo asowner/repo, whenever it has one. Without it a Maven coordinate usually comes backuntracked. Measured on this catalog:JetBrains/kotlin,google/ksp,square/okhttp,InsertKoinIO/koin,coil-kt/coil,tink-crypto/tink-java,robolectric/robolectric,pinterest/ktlint,detekt/detekt,gradle/gradle.
-
Check
matchbefore you read anything.match.slugmust be the library you meant. A note that says "Matched by name only" is a guess, and it can be wrong:com.android.tools.build:gradle(AGP, andapksigrides the same version) matches Gradle, the build tool, by name. Call it withname: "android-gradle-plugin"instead.- For androidx and other Google libraries with no GitHub repo, the coordinate comes back
untracked. Calllist_productswith the library's product name, then retryupgrade_noteswith that slug asname. Measured:cameraxandroomresolve this way; Compose, lifecycle, core, activity, navigation and datastore are not tracked. - Discard a result whose slug is some other product. Don't report its notes.
-
Read the result per dependency.
status: ok: start withsignals(major bump, breaking mentions, removed and deprecated counts,cves), then read each entry inreleasesfor itssections(breaking, security, deprecated, migration). The dependency'schangesis the categorized list across the whole interval. A section'sundernames the sub-package in a monorepo release; skip sections about artifacts this app doesn't use.untracked,unversioned,unreadable: What's New has no usable history for it. Read the vendor's notes yourself and say so.noteslike "is not tracked yet; the newest we track is …": the target version is newer than the tracked history (common with a same-week release), or it is a pre-release. The history holds stable releases only, so thedetekt2.0.0-alpha line and similar return no notes. Fall back to the vendor's notes for that stretch.truncatedor a cut change list: open the release'surlorsourceUrlfor the rest before concluding there is nothing breaking.
-
Act on it. Apply migrations the notes call for in the same change as the bump. Report to the user, per dependency: breaking items that touch code or config this repo uses, CVEs fixed, and anything unchecked because it was untracked. Don't paste the whole payload. Then follow
.agents/rules/build-and-test.md(regenerate every lock, then./gradlew lint).
Signals
- GitHub stars
- 116
- Forks
- 9
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
upgrade-notes- Source
- github.com/getknit/knit