Dependency Upgrade Agent

aka “Dependency Upgrader” in the catalogOutdated and vulnerable dependencies caught, the upgrade prepared and tested on a branch, the changelog risk spelled out. A draft PR you merge, never one that merges itself.

Qoren environment/dependency-upgrader-agent
online
  • Weekly Upgrade SweepWeekly on Monday at 06:00
  • Critical Cve WatchDaily
  • Monthly Dependency ReportMonthly on day 1 at 06:00

Category

Engineering

Runtime

Hermes

deploy dependency-upgrader --runtime managed

schedule tasks --timezone workspace

✓ agent online · monitoring

The Dependency Upgrade Agent, on autopilot

Each task runs on its own schedule in a managed environment. Adjust any of them, or add your own.

Schedule3
  • task #01Weekly Upgrade SweepWeekly on Monday at 06:00
  • task #02Critical Cve WatchDaily
  • task #03Monthly Dependency ReportMonthly on day 1 at 06:00

Weekly on Monday at 06:00

Weekly Upgrade Sweep

Run the weekly upgrade sweep. For each repo in ~/workspace/REPOS.md: enumerate outdated and vulnerable DIRECT dependencies and rank them: severity first, then major→minor→patch risk. For the top N per ~/workspace/UPGRAD…

Daily

Critical Cve Watch

Hourly: check for newly published security advisories (GitHub advisory data; Snyk too if configured) affecting a pinned dependency in a repo listed in ~/workspace/REPOS.md, new since ~/state/deps-seen.json (update it; e…

Monthly on day 1 at 06:00

Monthly Dependency Report

Send the monthly dependency report: how far behind each repo is (major/minor/patch counts), packages that are EOL or unmaintained, upgrade PRs merged vs. still open, and the honest risk of not upgrading the laggards. On…

What it delivers

A sample of what the Dependency Upgrade Agent produces. Illustrative, with fictional data.

Example delivery
Example output

Weekly Upgrade Sweep · Weekly on Monday at 06:00

Run the weekly upgrade sweep. For each repo in ~/workspace/REPOS.md: enumerate outdated and vulnerable DIRECT dependencies and rank them: severity first, then major→minor→patch risk. For the top N per ~/workspace/UPGRAD…

Delivered to your inbox, Slack, or Telegram.

Keeps its own workspace

The agent maintains a persistent workspace between runs, so context carries forward instead of starting from scratch every time.

workspace
  • 01Who the owner is: business, timezone, quiet hours, delivery channel
  • 02Watched repos with each one's package manager and exact test command, plus protected dependencies never to touch
  • 03How eagerly to upgrade: patch/minor freely, majors as migration notes only, batch sizes, never-upgrade list

Deploy this template and Qoren provisions a dedicated, managed cloud environment: no Docker, VPS, or server upkeep. Tailor the persona, schedules, and tools, use the managed model key or bring your own, and the agent stays online with activity, usage, and spend in one dashboard.

How deployment worksSee pricing

Category
Engineering
Runtime
Hermes
Scheduled tasks
3
Hosting
Fully managed

Dependency Upgrade Agent template questions

What does the Dependency Upgrade Agent template do?

Outdated and vulnerable dependencies caught, the upgrade prepared and tested on a branch, the changelog risk spelled out. A draft PR you merge, never one that merges itself. It runs 3 scheduled tasks on a managed cloud environment.

Which runtime does the Dependency Upgrade Agent use?

It runs on the Hermes runtime in a dedicated cloud environment that Qoren provisions and keeps online for you.

How often does the Dependency Upgrade Agent run?

On a schedule you control. Out of the box it runs weekly on monday at 06:00, daily, monthly on day 1 at 06:00. You can change the cadence, or trigger it on demand.

Will the Dependency Upgrade Agent do things without my approval?

No. It drafts and prepares the work, and you stay in control of anything that leaves your business. A reply, an invoice reminder, or a public post is written for your approval, not sent on its own.

What do I need to connect before it works?

Start from the template and connect the tools it needs, then set a model key: use the managed key included with your plan, or bring your own on any plan. The Dependency Upgrade Agent runs on the Hermes runtime.

Templates that pair well with this one.

Deploy it alongside these to cover the whole workflow.

Explore use cases

Deploy the Dependency Upgrade Agent today.

Sign in, start from this template, and go live in minutes. Plans from $39/mo.