Skip to content
Back to skills

Security Upgrade

ASecurity

Use when you need to scan project dependencies for CVEs, upgrade vulnerable packages, validate that everything still compiles and passes tests, then commit and push the fixes - works with npm, Go, Python, Rust, and Flutter projects.

  • 8 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 6, 2026
ai-agentspythonrustgobashnodegitapici/cdsecurity

Works with

  • api

Security analysis

A96/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned October 6, 2026

npx -y skills add bordenet/superpowers-plus --skill security-upgrade --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Upgrade?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Upgrade
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/bordenet-security-upgrade/badge)](https://www.skillsdirectory.com/skills/bordenet-security-upgrade)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-upgrade
disable-model-invocation: true
source: superpowers-plus
triggers: ["scan for CVEs", "upgrade vulnerable packages", "dependency security audit", "npm audit", "dependency vulnerabilities"]
anti_triggers: ["scan for secrets in code", "exposed credentials", "hardcoded password"]
description: Use when you need to scan project dependencies for CVEs, upgrade vulnerable packages, validate that everything still compiles and passes tests, then commit and push the fixes - works with npm, Go, Python, Rust, and Flutter projects.
summary: "Use when: upgrading dependencies for security fixes."
coordination:
  group: security
  order: 1
  requires: []
  enables: []
  escalates_to: []
  internal: false
composition:
  consumes: [code-changes]
  produces: [upgraded-dependencies]
  capabilities: [scans-cves, upgrades-packages]
  priority: 20
---

# Security Dependency Upgrade Workflow

> **Last Updated:** 2026-01-31
>
> **Wrong skill?** Full repo security scan (secrets, code patterns) → `repo-security-scan`. Public repo IP leakage → `public-repo-ip-audit`. Wiki content secrets → `wiki-secret-audit`.

## Workflow Summary

This skill provides a systematic workflow for security dependency auditing and upgrading. Use it to scan for CVEs, upgrade vulnerable packages, validate changes, and commit fixes.

**Supported package managers:** npm, Go modules, pip, Cargo, Flutter/pub

## Companion Skills

- **repo-security-scan**: Full security audit (this skill handles upgrades)
- **pre-commit-gate**: Pre-commit checks after security upgrades

## When to Use

- Monthly security audits of dependencies
- Before major releases to ensure clean security posture
- When dependabot or security alerts notify you of vulnerabilities
- After onboarding a new project to assess security debt
- CI/CD integration for automated security gates

## Phase 1: Discovery

Identify what package managers are in use:

```bash
# Find all dependency manifests
find . -name "package.json" -not -path "*/node_modules/*" -exec dirname {} \;
find . -name "go.mod" -exec dirname {} \;
find . -name "pubspec.yaml" -exec dirname {} \;
find . -name "requirements.txt" -exec dirname {} \;
find . -name "Cargo.toml" -exec dirname {} \;
```

## Phase 2: Security Scanning

### npm Dependencies

```bash
npm audit --json

# For monorepos
find . -name "package.json" -not -path "*/node_modules/*" \
  -exec sh -c 'echo "=== $(dirname {}) ===" && cd $(dirname {}) && npm audit' \;
```

### Go Dependencies

```bash
# Install if needed
go install golang.org/x/vuln/cmd/govulncheck@latest

# Scan
~/go/bin/govulncheck .

# Verbose with fix recommendations
~/go/bin/govulncheck -show verbose .
```

### Python Dependencies

```bash
pip install pip-audit
pip-audit
pip-audit -r requirements.txt
```

### Rust Dependencies

```bash
cargo install cargo-audit
cargo audit
```

### Flutter/Dart Dependencies

```bash
flutter pub outdated
```

## Phase 3: Upgrade Dependencies

| Language | Upgrade | Build | Test |
|----------|---------|-------|------|
| Go | `go get <pkg>@<ver> && go mod tidy` | `go build -o /dev/null .` | `go test ./...` |
| npm | `npm audit fix [--force]` | `npm run build` | `npm test` |
| Python | `pip install --upgrade <pkg>` | — | `pytest` |
| Rust | `cargo update <pkg>` | `cargo build` | `cargo test` |
| Flutter | update `pubspec.yaml` | `flutter build web --release` | `flutter test` |

## Phase 4: Validation

Build → test → security re-scan. Expected: "No vulnerabilities found."

## Phase 5: Commit & Push (only if ALL pass)

```bash
git commit -m "security: upgrade dependencies to fix CVEs

<Package> <old-version> → <new-version> (CVE-XXXX-XXXXX)
- Brief description of vulnerability fixed

Validation: All tests passing"

git push origin main
```

## Critical Reminders

1. **Always run full validation suite** before committing
2. **Document all CVE numbers** in commit message
3. **Test compilation** of all affected modules
4. **Re-scan for vulnerabilities** after upgrades to verify fixes
5. **Never bypass security updates** - all CVEs must be addressed

## ⛔ NEVER Do These Things

- **NEVER skip, disable, or bypass tests** to make upgrades pass
- **NEVER use `--force` flags** without explicit user approval
- **NEVER delete or comment out failing tests** to hide breakage
- **NEVER use `|| true` to suppress test failures**
- **NEVER commit with failing tests** - fix the code or rollback the upgrade

If tests fail after an upgrade, the correct response is:

1. Investigate why the test fails
2. Fix the code to work with the new dependency version
3. OR rollback to the previous dependency version
4. OR ask the user for guidance

## Expected Outcomes

- ✅ Zero known security vulnerabilities in dependencies
- ✅ All modules compile without errors
- ✅ All tests pass
- ✅ Changes committed and pushed

## Troubleshooting

**If govulncheck panics:**

- Run on individual directories instead of entire codebase
- Exclude template directories with Go files in node_modules

**If validation fails:**

- Do NOT commit or push
- Fix issues before proceeding
- Re-run validation suite

**If breaking changes introduced:**

- Review package changelogs
- Update code to accommodate API changes
- Consider gradual rollout for major version bumps

## Failure Modes

| Failure | Fix |
|---------|-----|
| `npm audit fix --force` silently introducing major version bumps | Review what `--force` will change BEFORE running; prefer `npm audit fix` first |
| Upgrading to version with breaking API changes without reading changelog | Check release notes/changelog for breaking changes before upgrading |
| Skipping transitive/indirect vulnerability fixes | Scan output includes indirect deps — trace and fix the root dependency |
| Tests pass locally but CI fails due to environment differences | Run full CI after push; don't declare "fixed" until CI confirms |

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…