{ "schema_version": 2, "kind": "shortening-method", "format": "agent-skill", "id": "dependency-update", "name": "Dependency update", "category": "Technical", "summary": "Shorten a package-update note to compatibility, evidence, and remaining work.", "use_cases": [ "Dependency pull requests", "Package upgrade reviews" ], "word_count": 152, "url": "https://sho.rten.it/methods/dependency-update/", "instructions_url": "https://sho.rten.it/methods/dependency-update/SKILL.md", "skill_url": "https://sho.rten.it/methods/dependency-update/SKILL.md", "json_url": "https://sho.rten.it/methods/dependency-update/llms.txt", "plain_text_url": "https://sho.rten.it/methods/dependency-update/prompt.txt", "license": "MIT", "sources_url": "https://sho.rten.it/sources/#dependency-update", "skill_name": "dependency-update", "skill_description": "Shorten a package-update note to compatibility, evidence, and remaining work. Use for Dependency pull requests, Package upgrade reviews.", "agents_md_url": "https://sho.rten.it/methods/dependency-update/AGENTS.md", "sources": [], "instructions": "Condense supplied information about a dependency update for a reviewer deciding whether the change is ready. Focus on the package boundary rather than a full application migration.\n\nName the package and old and new versions. State why the update is proposed. Keep relevant breaking changes, runtime requirements, transitive changes, configuration edits, and known regressions. Distinguish an upstream release claim from behavior verified in this project.\n\nGroup validation by what actually ran and what remains untested. Keep exact test outcomes, platform limits, and unresolved blockers. Remove unrelated release-note entries, repeated version lists, and routine bot narration. Do not infer safety from a patch version or call an update security-related without source evidence.\n\nOutput Change, Impact, and Validation, plus Remaining work when supplied. Preserve whether the update is proposed, merged, or deployed. Do not install packages, approve the update, or turn a passing unit suite into a claim that all integration behavior is compatible.", "example": { "context": "Dependency upgrade review", "before": "This pull request proposes updating queue-client from 2.4.1 to 3.0.0. We need the new server-side cancellation API. Upstream 3.0.0 requires Node.js 20 or later and removes the retryDelay option in favor of retryDelayMs. Our application already uses Node.js 22, and this PR renames that option without changing its value of 500. All 146 unit tests passed locally on Linux. The integration suite did not run because its test broker was unavailable. Upstream says reconnect handling is improved, but we have not verified that behavior in our application. The update is not merged or deployed.", "after": "Change: Proposed queue-client 2.4.1 → 3.0.0 for server-side cancellation; not merged or deployed.\nImpact: Requires Node.js ≥20; app uses 22. retryDelay becomes retryDelayMs; value remains 500.\nValidation: 146 unit tests passed locally on Linux. Upstream reconnect improvements are unverified here.\nRemaining work: Integration suite could not run; test broker unavailable.", "must_preserve": [ "Proposed queue-client 2.4.1 to 3.0.0; server-side cancellation reason", "Requires Node.js 20+; app uses Node.js 22", "retryDelay replaced with retryDelayMs; 500 unchanged", "146 local Linux unit tests passed", "Integration tests not run due unavailable broker", "Upstream reconnect claim unverified in app; not merged or deployed" ], "kind": "illustrative", "omitted": [ "First-person narration and repeated references to this pull request and application." ] } }