update-dependencies

A workspace command for updating project packages and checking which ones are still out of date. It also handles Nx package migrations and keeps certain packages within specified major or minor versions.

In plain words
What is it for?
Use it to refresh dependencies in a pnpm workspace, find remaining outdated packages, update Nx, and adjust exact package versions and recorded package versions.
Why use it?
It reduces the manual work of finding outdated packages across multiple projects and applying the required Nx migration steps. Version limits help avoid upgrades that the workspace does not allow.

Command for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/phuctm97/modelfetch/update-dependencies
Clone the repo
git clone --depth 1 https://github.com/phuctm97/modelfetch

Made for: Claude Code.

Per session 6 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 553 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00006 $0.00553
Opus 5 $0.00003 $0.00277
Sonnet 5 $0.00001 $0.00111
Haiku 4.5 $0.00001 $0.00055

Measured 2d ago against content hash 20fa5e46e36b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

update-dependencies scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/commands/update-dependencies.md · 41 lines

What it actually says

Update all dependencies in the workspace.

Execute the following steps in order:

  1. Update all dependencies: Run pnpm -r up to update all dependencies in all projects to their latest versions

  2. Check for outdated dependencies: Run pnpm -r outdated to identify any dependencies that are still outdated

  3. Update Nx packages: If any Nx packages (nx or @nx/*) are outdated:

    • Run pnpm exec nx migrate latest to update Nx and its plugins
    • Follow any migration instructions provided by the command
  4. Manually update exact versions: For any remaining dependencies using exact versions that are outdated:

    • Read the relevant package.json files
    • Update the exact versions to the latest available versions
    • Apply the following exceptions:
      • zod: Keep at latest version 3.x.x (do not upgrade to 4 or higher)
      • typescript: Keep at latest version 5.9.x (do not upgrade to 5.10 or higher)
      • @types/node: Keep at latest version 22.x.x (do not upgrade to 23 or higher)
  5. Update packageVersions in create-modelfetch:

    • Read libs/create-modelfetch/src/index.ts
    • Check the current versions of all packages in the workspace by running pnpm list --depth=0 in relevant project directories
    • Update the packageVersions object with the new exact versions that are installed
    • Make sure to respect the same exceptions (zod v3, typescript v5.9, @types/node v22)
  6. Install updated dependencies: After manually updating any exact versions, run pnpm install to install the updated dependencies

  7. Verify updates: Run pnpm -r outdated again to confirm all dependencies are up to date (except for the specified exceptions)

Important notes:

  • For exact versions, update to the latest available version unless it conflicts with the exceptions
  • The exceptions should use the latest patch/minor version within their specified major/minor constraints
  • The packageVersions object in create-modelfetch should reflect the actual versions installed in the workspace
  • If any dependency update causes conflicts, report them to the user for resolution
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 41 lines · 6 tokens per session scan A 20fa5e46e36b

Subscribe to this mod's changes

update-dependencies is a command published in the GitHub repository phuctm97/modelfetch (145 stars, last pushed 8mo ago), licensed MIT. It adds 6 tokens to every session and 553 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.