insomnia.club back to site
[ playbook · engineering ]

A dependency upgrade agent that finishes the pull requests bots open

Update bots are good at opening pull requests and bad at finishing them. An agent picks up each upgrade, reads the changelog and migration guide, makes the code changes the new version requires, and iterates until CI passes, leaving a clear explanation for the engineer who approves it.

who owns it

Platform or infrastructure lead responsible for dependency health

what starts it

An update bot opens a pull request, or a security advisory lands for a dependency in use

01the problem and who owns it

Every repository has a column of red dependency pull requests nobody wants to touch. Patch updates merge; major versions sit for months because each one needs someone to read a migration guide and fix dozens of call sites. The longer they sit, the bigger the eventual jump.

The platform lead owns dependency health and the security team owns the advisories, but neither has engineers to spare for upgrade toil. When a critical vulnerability lands in a library three major versions behind, the fix becomes a project instead of a patch.

02what the AI does, step by step

  1. Pick up the upgradeWhen Dependabot or Renovate opens a pull request, or an advisory names a vulnerable version, the agent checks out the branch and records the current CI result as its starting point.
  2. Read what changedIt retrieves the release notes, changelog, and migration guide for every version between current and target, and extracts breaking changes, deprecations, and renamed APIs relevant to how this codebase uses the package.
  3. Find affected call sitesStatic search and the type checker locate every usage of changed APIs. The agent builds a list of edits before writing any, so the plan can be reviewed if the change is large.
  4. Apply the changes and iterateIt makes the edits, runs the build, type checks, and tests, reads the failures, and fixes them in a loop with a cap on attempts. Official codemods are used where the library provides them.
  5. Stop at the right momentIf the upgrade requires a behavior decision, such as a changed default, or the attempt cap is reached, the agent stops and writes up exactly what is left rather than forcing tests green.
  6. Explain the pull requestThe description lists breaking changes found, edits made, tests adjusted and why, and anything a reviewer should check by hand. Test changes are called out separately so weakened assertions are visible.

03systems it connects to

04human checkpoints

05what to measure

06risks and guardrails

07build vs buy

Dependabot and Renovate are free and handle the opening and grouping of updates well. Many libraries ship codemods for their own major versions, and some vendors sell managed upgrade services for popular frameworks.

An agent on top of those tools pays off when you run many repositories, carry a large backlog of major upgrades, or need security patches to land quickly in code that is several versions behind.

Browse every engineering playbook or the full library.

want this running in your business?

We can take your oldest dependency backlog on one repository, run the agent against it with your CI, and show you which upgrades it finished and exactly where it stopped.

See how we deliver it: ai coding orchestration.

book a call drop your number

info@insomnia.club