🧨Dependency Update Risk Check Guide

Tally the version jump and the checks, with no score

%
This page does not produce a risk score or grade. There is no official basis for the weights, so it checks items, tallies which ones apply and explains why each matters. Scoring complexity from module and relationship counts belongs to a separate tool.

You Might Also Need

Tally what to check before you update

Deciding what to look at before bumping a dependency does not end with the version numbers. Enter the current and target versions, what the changelog says, your test coverage, the transitive dependency count and the maintainer count, and this page tallies how many items need a look and lists why each one matters.

The version jump is judged against SemVer 2.0.0. A major change signals that compatibility may break, and skipping two or more major versions means the notes in between go unread. On 0.y.z the specification guarantees no compatibility, so even a minor bump can break. A target lower than the current version is flagged separately as a downgrade. Current as of October 2026.

This page produces no risk score or grade. There is no official basis for weighting the items, so a score would only look precise. There is also no baseline coverage percentage that makes an update safe, so the figures are shown as they are. Querying package registries and reading the actual changelog are not supported, so the values have to be checked and entered by hand.

Frequently Asked Questions

Why is there no risk score?

Because there is no official basis for weighting the items. A score would only make a guess look precise, so the page checks items and tallies how many apply instead.

Is 0.9.0 to 0.10.0 a safe update?

The specification treats 0.y.z as initial development and guarantees no compatibility, so even a minor bump can break. That case is flagged as an item to look at.

What coverage percentage is enough?

There is no official baseline. This page suggests none; it only computes the uncovered share and points out that breakage there stays hidden after the update.