General · inspect by default

/deps

Assess dependency updates and compatibility

Use for dependency assessment or requested updates; vite-upgrade handles Vite-specific migration behavior and security-fix remediates a confirmed advisory.

Make it your own.

In Claude Code, use the slash command and add your context. In Codex, select deps from the just-vibe skill picker, then send the same brief.

Version 0.11.0 also supports /jv deps, /just-vibe deps and /jv:deps in Claude. See shortcut setup and context examples.

Example · inspect
/just-vibe:deps Assess a compatible dependency update without changing files yet.
edge · apply
/just-vibe:deps Update one dependency with a conflicting peer and an unrelated dirty lockfile.
blocked · inspect
/just-vibe:deps Assess dependencies from the lockfile with unavailable advisory access.

What the agent does

  1. Read manifests, resolved versions and peer/runtime ranges, and identify why each dependency exists.
  2. Check current release notes and advisories, and group changes by risk, isolating direct changes from lockfile churn.
  3. In apply mode, change the manifest through the project's package manager, then inspect the lockfile diff for unrelated churn before running checks.

Inputs

  • package scope, update goal, compatibility constraints, and registry access when needed.

Optional context: scope, references, constraints, successCriteria, environment, mode, budget.

Scope

Reads
Dependency health and upgrade proposals; a requested update uses apply mode and includes lockfiles.
Writes
Inspect/plan: inspect or propose; save requested artifacts only. Apply: edit the requested local implementation and perform relevant bounded checks while preserving unrelated work. Live data changes, remote actions and paid jobs require their resolved target and existing session authorization.
Mode
Inspect; package scope, update goal, compatibility constraints, and registry access when needed. Apply for a requested update through the project's package manager.
Prerequisites
Resolve the user brief and inspect the relevant project or supplied evidence. External capabilities are optional unless the selected action actually needs them.

Expected output

  • Current/target versions with compatibility risks and advisory evidence, and prioritized recommendations or, in apply mode, the requested update with its checks.

How the work is checked

  • A peer conflict is detected; updating one package does not silently churn unrelated dependency versions.

When to stop or clarify

  • Never treat latest as automatically best. Missing registry information is unknown, not proof of no vulnerabilities.

Handling missing context

Infer
Resolve the named files, existing scripts, current task and earlier corrections from the conversation and repository.
Assume
Use the narrowest interpretation that completes a reversible local task; state a consequential assumption once.
Ask
Ask when competing targets or incompatible success conditions would change the result; continue independent inspection first.

Technical guidance

Evidence
Inspect manifests, lockfiles, direct/transitive ownership, advisory evidence and supported versions.
Method
Separate security fixes from routine upgrades and assess API/engine/peer compatibility before changing the resolved graph.
Pitfall
Forced audit fixes or ignored peer conflicts can replace one issue with a runtime incompatibility.
Check
Inspect the resulting lockfile, run relevant behavior/build checks and retain unresolved advisories or inaccessible registry evidence.

Situational decisions

When an advisory has configuration-dependent exposure: Trace actual reachable use and report that condition before recommending a breaking upgrade.

The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.

Keep exploring