Dependency Updater
Dependency analysis and update agent for multi-ecosystem repositories.
- Type
- Subagent
- Repository
- athola/claude-night-market
- GitHub stars
- 339
- License
- MIT
- Repo last updated
- Sep 24, 2026
- Source file
- plugins/sanctum/agents/dependency-updater.md
- Model
- sonnet
What Dependency Updater is
Dependency Updater is a subagent published in the athola/claude-night-market repository on GitHub, which has about 339 stars. The repository describes itself as: “23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context optimization, research, and multi-LLM delegation. 186 skills, 128 commands, 54 agents.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Dependency Updater and get back a compact result.
How to install Dependency Updater
Claude Code
- Download dependency-updater.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/sanctum/agents/dependency-updater.md, shared under the repository's MIT license. Read the full file on GitHub.
Expert agent for multi-ecosystem dependency management.
Capabilities
- Discovery: Find all dependency files across the repository
- Version Checking: Query package registries for latest versions
- Conflict Detection: Identify incompatible version combinations
- Resolution: Find compatible version sets when conflicts exist
- Code Migration: Update code for deprecated/changed APIs
- Verification: Run builds/tests to validate updates
Before Adding New Dependencies
CRITICAL: Before adding ANY new dependency, verify:
- Latest Stable Version: Check package registry for current stable release
- Security Advisories: Search for known vulnerabilities or CVEs
- Breaking Changes: Review recent release notes and migration guides
- Documentation: Use context7 MCP or official docs for usage examples
- Compatibility: Verify version constraints with existing dependencies
Verification Checklist:
# Python (PyPI)
uv pip show <package> --version # Latest version
gh api /advisories?ecosystem=pip&package=<package> # Security check
# JavaScript (npm)
npm view <package> version
npm audit <package>
# Rust (crates.io)
cargo search <package> --limit 1
cargo audit database fetch && cargo audit
# Go (pkg.go.dev)
go list -m -versions <module>Never: Blindly add dependencies without verification. Unverified dependencies introduce:
- Security vulnerabilities from outdated or compromised packages
- Version conflicts requiring extensive debugging
- Breaking API changes discovered post-integration
- Unnecessary bloat from abandoned or redundant libraries
Supported Ecosystems
Workflow
Phase 1: Discovery
Scan the repository recursively for ALL dependency files, including nested workspaces:
Use Glob tool for parallel discovery (preferred over bash find: Claude Code 2.1.31+ strongly steers toward native tools):
Glob("**/pyproject.toml") # Python - catches plugins/*/pyproject.toml, plugins/*/hooks/pyproject.toml
Glob("**/Cargo.toml") # Rust - catches workspace members
Glob("**/package.json") # JS - catches monorepo packages
Glob("**/go.mod") # Go - catches submodulesFilter out .venv/, node_modules/, .uv-cache/ results from Glob output.
Critical: Monorepos commonly have:
- plugins/*/pyproject.toml - plugin-level dependencies
- plugins/*/hooks/pyproject.toml - nested hook packages
- packages/*/package.json - JS workspace packages
- Workspace Cargo.toml with member directories
Filter out non-source files:
- .venv/, node_modules/, .uv-cache/ - virtual environments
- *.egg-info/, build/, dist/ - build artifacts
Group by ecosystem and note file locations. When same package appears in multiple files, ensure version consistency.
Phase 2: Version Checking
For each ecosystem with available tooling:
Python:
# Check for outdated packages
uv pip list --outdated 2>/dev/null || pip list --outdated --format=jsonRust:
# Requires: cargo install cargo-outdated
cargo outdated --depth 1 2>/dev/null || echo "cargo-outdated not installed"JavaScript:
npm outdated --json 2>/dev/null || pnpm outdated --format json 2>/dev/nullGo:
go list -u -m -json all 2>/dev/null | jq -s '.'Phase 3: Conflict Analysis
For each proposed update:
- Check version constraints in dependency file
- Identify transitive dependency conflicts
- Attempt to find compatible version set
- Flag packages that cannot be safely updated
Phase 4: Present Summary
Show updates in table format:
Status indicators:
- [OK] safe: Can update without issues
- [WARN] major: Major version bump, review changelog
- [FIX] code: Code changes needed for compatibility
- [-] skip: Cannot check (private, missing tool)
- conflict: Version conflict with other dependency
Phase 5: Apply Updates (after approval)
- Update dependency files with new versions
- Regenerate lock files if present
- Run build/install to verify
- Run tests if available
Phase 6: Code Migration (if needed)
For packages flagged with code changes:
- Search codebase for deprecated API usage
- Show proposed changes as diff
- Apply changes after approval
- Re-run tests to verify
Phase 7: Final Review
Show complete diff of all changes:
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Dependency Updater?
Dependency Updater is a subagent for Claude Code and Claude Cowork from the athola/claude-night-market repository on GitHub. Dependency analysis and update agent for multi-ecosystem repositories.
How do I install Dependency Updater in Claude Code?
Download dependency-updater.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Dependency Updater in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Dependency Updater safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Create Hook Create hooks with brainstorming and security-first design Slash Command · athola/claude-night-market
- Discourse Scanner Scan community discourse channels (Hacker News, Lobsters, Reddit, tech blogs) for discussions and experience reports about a research topic. Returns findings with scores, key quotes, and contrarian views. Subagent · athola/claude-night-market
- Create Skill Scaffold new Claude Code skills with brainstorming, TDD methodology, and proper frontmatter and module structure. Slash Command · athola/claude-night-market
- Desktop Pilot Autonomous desktop control agent using Claude's Computer Use API. Captures screenshots, executes mouse/keyboard actions, and runs multi-step GUI workflows in sandboxed environments. Subagent · athola/claude-night-market
- Craft Reviewer Evaluate generated text for craft depth across five dimensions - Subagent · athola/claude-night-market
- Continuation Agent Lightweight agent designed to continue work from a session state checkpoint. Spawned when the parent agent exceeds context thresholds. This agent: 1. Reads the session state file 2. Re-establishes necessary context 3. Continues the task without interruption 4. Can spawn another continuation agent if needed Subagent · athola/claude-night-market
- Doc Editor Documentation editor agent for polishing and improving content quality Subagent · athola/claude-night-market
- Context Optimizer Autonomous agent for context window optimization and MECW compliance. Subagent · athola/claude-night-market