Upgrade Python Dependencies

VerifiedSafe

Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken.

Sby Skills Guide Bot
DevelopmentIntermediate
108/29/2026
Claude CodeCursorWindsurfCopilotCodex
#python#uv#dependency-upgrade#testing#maintenance

Recommended for

Our review

Upgrades all Python dependencies using uv with a 7-day cooldown, then runs type checking and tests to verify nothing is broken.

Strengths

  • Uses uv for fast and reliable dependency resolution
  • Enforces a 7-day grace period to reduce supply-chain risks
  • Runs mypy and tests to catch regressions
  • Commits changes via the /commit skill

Limitations

  • Assumes uv and make are already installed
  • The 7-day cooldown may delay important security updates
  • Some dependency changes may require manual intervention beyond automated checks
When to use it

Use when you need to refresh Python dependencies in a project and verify compatibility before committing.

When not to use it

Do not use for projects that do not use uv or Python, or when you need to upgrade a specific package only.

Security analysis

Safe
Quality score90/100

The skill only invokes uv commands to upgrade dependencies, sync the environment, run tests, and type checking. It includes a 7-day cooldown to mitigate supply-chain attacks and checks for conflicts. No destructive, exfiltrating, or obfuscated actions are present.

No concerns found

Examples

Upgrade all dependencies and test
Upgrade all Python dependencies in this project and make sure the tests still pass.
Full upgrade with checks
Run uv lock --upgrade --exclude-newer '7 days' and then sync and run mypy and make test.
Upgrade and commit if green
Update the Python dependencies, check for type errors, and run the test suite. If everything passes, commit the changes.

name: upgrade-python-deps description: Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken. allowed-tools: [ Bash(uv lock *), Bash(uv sync *), Bash(make test *), Bash(uv run mypy *), ]

Your task

Upgrade all Python dependencies and verify nothing is broken.

Step 1: Upgrade the lock file

Run uv lock --upgrade --exclude-newer "7 days" to upgrade all dependencies to their latest compatible versions (with a 7-day cooldown to mitigate supply-chain attacks).

Review the output for any resolution errors. If there are conflicts, report them to the user and ask how to proceed before continuing.

Step 2: Sync the environment

Run uv sync to install the upgraded dependencies into the virtual environment.

Step 3: Run post-upgrade checks

Run these checks sequentially, stopping if any step fails:

  • Type checking: Run uv run mypy . and report any new type errors. These may be caused by updated type stubs or changes in library APIs.
  • Tests: Run make test to verify the test suite still passes.

Step 4: Summarize and commit

Summarize what was done:

  • Which packages were upgraded (notable version changes)
  • Whether any type errors were introduced
  • Whether all tests passed
  • Any issues that need manual attention

If there were failures, present the issues and ask how the user wants to proceed.

If everything passed, ask the user if they'd like to commit the changes. If yes, commit using the /commit skill.

Related skills