Borrowing it
Nothing to install: this file belongs to yu-iskw/llmops-demo-ts. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/yu-iskw/llmops-demo-ts/main/.cursor/commands/upgrade-dependencies.mdgit clone --depth 1 https://github.com/yu-iskw/llmops-demo-tsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/yu-iskw/llmops-demo-ts/upgrade-dependencies)<a href="https://agentmods.dev/commands/yu-iskw/llmops-demo-ts/upgrade-dependencies"><img src="https://agentmods.dev/badge/commands/yu-iskw/llmops-demo-ts/upgrade-dependencies/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/yu-iskw/llmops-demo-ts/upgrade-dependencies"><img src="https://agentmods.dev/badge/commands/yu-iskw/llmops-demo-ts/upgrade-dependencies.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00612 |
| Opus 5 | $0.00000 | $0.00306 |
| Sonnet 5 | $0.00000 | $0.00122 |
| Haiku 4.5 | $0.00000 | $0.00061 |
Grade A, and why
upgrade-dependencies scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 85 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Upgrade Dependencies
This command upgrades all dependencies in the workspace to their latest compatible versions using pnpm.
Steps
- Upgrade Dependencies: Run
pnpm up -rto upgrade all dependencies recursively across workspace packages within their specified version ranges - Update Lockfile: Run
pnpm installto ensure the lockfile reflects the changes - Verify Build: Run the full build process to ensure no breaking changes
- Check for Issues: Review any warnings about deprecated packages or peer dependency conflicts
Prerequisites
pnpmmust be installed- All packages should be committed to git (for easy rollback if needed)
- Tests should be passing before upgrading
Usage
Run this command from the project root directory. Execute these steps:
-
Upgrade dependencies recursively across all workspace packages:
pnpm up -r -
Update lockfile:
pnpm install -
Verify build:
pnpm build -
Check for issues:
- Review any warnings about deprecated packages
- Check for peer dependency conflicts
- Verify build script warnings
What Gets Updated
The command updates:
- Runtime dependencies: Packages listed in
dependenciessections across all workspace packages - Development dependencies: Packages listed in
devDependenciessections across all workspace packages - Lockfile:
pnpm-lock.yamlis updated with new package versions and integrity hashes
Recursive Operations
The -r flag ensures the upgrade operation runs across all packages in the workspace simultaneously, respecting each package's individual version constraints.
Safety Considerations
- Version Ranges: Only upgrades within the version ranges specified in
package.json(respects^and~constraints) - Breaking Changes: Major version upgrades may introduce breaking changes - review changelogs
- Testing: Always run full test suite after upgrading
- Git: Commit before upgrading to enable easy rollback
- Peer Dependencies: Check for any peer dependency warnings that may require manual resolution
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 85 lines · 0 tokens per session scan A 4e5a6b1bfaef
upgrade-dependencies is a command published in the GitHub repository yu-iskw/llmops-demo-ts (6 stars, last pushed 9d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 612 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.
Other commands, from other repositories
awesome-chatgpt
Search awesome-ChatGPT-repositories for open-source GitHub repositories related to ChatGPT and LLMs.
expect
Diff-aware AI browser testing — reads the git diff, maps changes to affected pages via the route map, generates a targeted test plan, and executes it via agent-browser (Rust daemon + CDP, ARIA-tree-first) with pass/fail reporting. Use when testing UI changes, verifying PRs before merge, or running regression checks on…
agentlas-local
Staff a task only from Agentlas agents registered on this machine.
speckit.archive
Archive a feature specification into main project memory after merge, resolving gaps and conflicts.
speckit.opsmill.retrospect
Run a session retrospective that surfaces context-management gaps and routes them to approved follow-up actions.
pr
Handle the full workflow from current branch state to an open, CI-monitored pull request.