Update Commands
On this page 35
Commands for scanning dependencies and creating pull requests with updates.
scan
Scan for dependency updates without making any changes.
Usage
buddy scan [options]
Options
--verbose, -v- Enable verbose logging--packages <names>- Comma-separated list of packages to check--pattern <pattern>- Glob pattern to match packages--strategy <type>- Update strategy: major|minor|patch|all (default: all)--ignore <names>- Comma-separated list of packages to ignore
Examples
# Basic scan
buddy scan
# Verbose output
buddy scan --verbose
# Scan specific packages
buddy scan --packages "react,typescript"
# Use glob patterns
buddy scan --pattern "@types/*"
# Scan with strategy filter
buddy scan --strategy minor
# Ignore specific packages
buddy scan --ignore "eslint,prettier"
Output
✓ Found 3 package updates
📦 Non-Major Dependencies (3 updates)
react: 18.2.0 → 18.3.1 (minor)
typescript: 5.3.3 → 5.4.2 (minor)
@types/node: 20.10.0 → 20.11.5 (minor)
🔒 Security: 0 packages
⚠️ Breaking: 0 packages
📈 Total: 3 packages ready for update
update
Update dependencies and create pull requests.
Usage
buddy update [options]
Options
--verbose, -v- Enable verbose logging--strategy <type>- Update strategy: major|minor|patch|all (default: all)--ignore <names>- Comma-separated list of packages to ignore--dry-run- Preview changes without making them
Examples
# Update all dependencies
buddy update
# Preview what would be updated
buddy update --dry-run
# Update only patch versions
buddy update --strategy patch
# Verbose output
buddy update --verbose
# Ignore specific packages
buddy update --ignore "@types/node,eslint"
Dry Run Output
🔍 Dry run mode - no changes will be made
Would create 2 pull request(s):
📝 chore(deps): update all non-major dependencies (3 updates)
📝 chore(deps): update dependency react to v19.0.0 (1 update)
Process Flow
- Scan: Analyzes project for outdated dependencies
- Group: Organizes updates by type (major/minor/patch)
- Branch: Creates feature branches with timestamp
- Commit: Updates package.json with new versions
- PR: Creates pull request with detailed information
- Labels: Applies dynamic labels based on update types
rebase
Rebase/retry a pull request with latest updates.
Usage
buddy rebase <pr-number> [options]
Parameters
<pr-number>- Pull request number to rebase
Options
--verbose, -v- Enable verbose logging--force- Force rebase even if PR appears up to date
Examples
# Rebase PR #17
buddy rebase 17
# Verbose rebase
buddy rebase 17 --verbose
# Force rebase even if up to date
buddy rebase 17 --force
Process
- Validation: Checks if PR exists and is a buddy PR
- Analysis: Extracts current package updates from PR body
- Comparison: Scans for latest versions
- Update: Updates existing PR in-place (preserves PR number)
- Notification: Updates PR content and labels
Output
🔄 Rebasing/retrying PR #17...
📋 Found PR: chore(deps): update dependencies
🌿 Branch: buddy/update-dependencies-1704123456789
📦 Found 2 packages to update
🔍 Checking if rebase is needed...
🔄 Updating PR with latest updates...
✅ Updated existing PR #17: chore(deps): update all non-major dependencies
🔗 https://github.com/your-org/your-repo/pull/17
update-check
Auto-detect and rebase PRs with checked rebase boxes.
Usage
buddy update-check [options]
Options
--verbose, -v- Enable verbose logging--dry-run- Check but don't actually rebase
Examples
# Check and rebase marked PRs
buddy update-check
# Preview what would be rebased
buddy update-check --dry-run
# Verbose output
buddy update-check --verbose
Rebase Checkbox Format
PRs include this checkbox for manual rebase triggers:
---
- [ ] <!-- rebase-check -->If you want to update/retry this PR, check this box
---
When checked (marked with x):
- [x] <!-- rebase-check -->If you want to update/retry this PR, check this box
Process
- Discovery: Finds all open buddy PRs
- Detection: Scans PR bodies for checked rebase boxes
- Validation: Extracts package updates from PR content
- Rebase: Updates each marked PR with latest versions
- Reset: Unchecks the rebase box after completion
Output
🔍 Checking for PRs with rebase checkbox enabled...
📋 Found 3 buddy PR(s)
🔄 PR #17 has rebase checkbox checked: chore(deps): update dependencies
🔄 Rebasing PR #17...
✅ Successfully rebased PR #17
🔄 PR #20 has rebase checkbox checked: chore(deps): update typescript
🔄 Rebasing PR #20...
✅ Successfully rebased PR #20
✅ Rebased 2 PR(s) successfully
Configuration Integration
All update commands respect configuration from buddy.config.ts:
Strategy Override
// Config strategy can be overridden by CLI
export default {
packages: {
strategy: 'patch' // Default strategy
}
}
# Override config strategy
buddy update --strategy minor
Ignore Lists
// Combine config and CLI ignore lists
export default {
packages: {
ignore: ['@types/node'] // Always ignored
}
}
# Additional ignores for this run
buddy update --ignore "eslint,prettier"
# Result: ignores @types/node, eslint, and prettier
Error Handling
Common Errors
Repository not configured:
❌ Repository configuration required for PR creation
Configure repository.provider, repository.owner, repository.name in buddy.config.ts
Missing GitHub token:
❌ GITHUB_TOKEN environment variable required for PR creation
Invalid PR number:
❌ Invalid PR number provided
PR not found:
❌ Could not find open PR #17
Not a buddy PR:
❌ PR #17 is not a buddy PR (branch: feature/custom-update)
Troubleshooting
No updates found:
- Check if packages are in ignore list
- Verify update strategy allows available updates
- Ensure dependencies are actually outdated
Permission errors:
- Verify GitHub token has correct permissions
- Check repository settings allow Actions to create PRs
- Use
buddy open-settingsfor quick access
Rebase fails:
- Ensure PR is still open
- Check if branch exists
- Verify PR contains valid package update information
Best Practices
Update Strategies
- Start Conservative: Use
patchstrategy initially - Test Major Updates: Always review breaking changes manually
- Group Related Updates: Let Buddy group ecosystem packages
- Monitor CI: Ensure tests pass before merging
PR Management
- Regular Rebasing: Use
update-checkin automation - Batch Reviews: Review multiple patch updates together
- Label Organization: Use labels for workflow automation
- Merge Hygiene: Use squash merging for clean history
Automation Integration
# .github/workflows/dependencies.yml
name: Dependency Updates
on:
schedule:
- cron: '0 2 _ _ 1' # Weekly on Monday
workflow_dispatch:
jobs:
update:
runs ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
- name: Install dependencies
run: bun install
- name: Update dependencies
run: bunx @buddysh/buddy update --strategy patch --verbose
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Auto-rebase existing PRs
run: bunx @buddysh/buddy update-check --verbose
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}