Contents

Frontend Development › Frontend Build Tooling

Keeping Dependencies Updated

Upgrading regularly, with tools like Dependabot or Renovate.

Also known as: dependency updates, keeping dependencies updated, updates

Keeping dependencies updated balances security and feature freshness against breakage risk: a cadence (weekly minor/patch batches, deliberate majors), automation (renovate/dependabot PRs with CI verdicts), and policy (pinning, ranges, lockfiles) that keeps updates flowing instead of accumulating into terrifying leaps.

weekly: automerge green patches/minors → monthly: review grouped updates
quarterly: plan majors (codemods, migration windows)

Stale dependencies compound: security holes unpatched, majors piling into one big-bang migration, ecosystem drift making every update an expedition. Small continuous updates are cheaper than rare heroic ones — the same logic as small deploys.

The classic mistakes:

  • Pinning everything forever. Frozen versions feel safe while vulnerabilities and incompatibilities accumulate silently. Pin strategically (lockfiles pin; manifests range).
  • Automerge without CI teeth. Auto-merging updates on weak test suites ships breakage automatically. Automation needs tests that actually verify; otherwise review manually.
  • Major-update pileup. Skipping majors for years turns each into a rewrite (React 15→19 in one jump). Budget majors continuously; migrate incrementally.
  • Ignoring transitive updates. Direct deps current while transitive vulnerable copies linger. Audit the tree (npm audit, lockfile review), not just package.json.
  • No rollback story. An update breaking production needs instant revert (redeploy previous lockfile), not forward-fix panic. Lockfiles versioned; deploys repeatable.
  • Changelog blindness. Merging without reading breaking-change notes misses migration steps. Majors get changelog review; minors get CI verdicts.
  • Update theatre. Bumping versions without running the app’s actual flows verifies nothing. Updates validate through real test suites and smoke checks.

The cadence: automate the small (patches/minors with CI), schedule the big (majors with migration plans), pin with lockfiles, review transitives. Freshness as habit, not heroics.