For straightforward package.json updates.
Use the website without an account. Sign in and create an access token for 10 free MCP updates per day.
Use the free updaterUpdate dependency ranges, tidy your manifest, and create a reviewable diff without leaving your browser.
Update package.json in your browser for free, or connect your AI assistant with 10 free MCP updates per day. Get Pro for a higher daily allowance.
For straightforward package.json updates.
Use the website without an account. Sign in and create an access token for 10 free MCP updates per day.
Use the free updaterYour assistant gets verified npm versions and the same update options you use here. Billed monthly in USD. Cancel anytime.
Included with Pro:
Use OAuth login or revocable access tokens to connect your tools.
MCP allowances reset daily at midnight UTC. Both plans allow 5,000 submitted dependency entries per day. Website updates are free and do not use your MCP allowance.
Everything the updater does is designed to make a small maintenance task stay small.
Bring in the manifest you already have. No repository connection or setup wizard needed.
Choose latest, newest, or next, then select the semver range written to each dependency.
See what changed, copy the clean result, and keep the final decision in your hands.
Practical notes for keeping package manifests healthy, readable, and easier to review.
Caret and tilde ranges look tiny, but they encode different maintenance policies. Learn how they behave across stable releases, 0.x packages, and prereleases.
6 min readA major bump is a migration, not a version-string edit. Use a staged workflow to read the release notes, isolate the change, test it, and roll it back cleanly.
9 min readOne file declares dependency intent and the other records the resolved tree. Understanding the difference makes installs reproducible and lockfile diffs easier to review.
7 min readBoth tools find newer versions, but only one is designed to rewrite your manifest. Compare their output, scope, flags, and safest workflow.
7 min readRead ERESOLVE as a constraint report, align the host and plugin versions, and use overrides or escape hatches only when you can explain the tradeoff.
10 min readShared manifests, workspace protocols, lockfiles, and focused tests help a monorepo keep routine dependency updates small and reviewable.
8 min readAudit alerts are the beginning of a security decision. Triage severity and reachability, choose the least risky fix, and document what you defer.
9 min readUpdating dependencies is one of those tasks that looks simple from a distance. Open package.json, change a few versions, reinstall, and move on. In practice, a dependency file is a compact record of compatibility decisions. A large or noisy edit makes it harder to tell which change caused a problem later.
6 min readEverything you need to make your next dependency update feel routine.