{"_id":"dep-up-surgeon","_rev":"32-4410203593b5b93892a1593f8fe29a83","name":"dep-up-surgeon","dist-tags":{"latest":"4.1.1"},"versions":{"1.0.0":{"name":"dep-up-surgeon","version":"1.0.0","keywords":[],"author":"","license":"ISC","_id":"dep-up-surgeon@1.0.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-all":"index.js"},"dist":{"shasum":"33e092ddd1f19eadf0157ef56e67dce8448519fc","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.0.0.tgz","fileCount":2,"integrity":"sha512-UI+dD3cigNlI8MrmaYAr3GfyhPdbeXBtgOgOckQeE0wNj/GXAVfcLsJZyNnaUGHD16lFzv2ZHmGMBWly1WQiLA==","signatures":[{"sig":"MEUCICioNdZlv5xxcWah/pOER9EPl1A2J7hiRZe7MpwCDnTlAiEA0a542HhLnZApV/7satje8uxOaDG8GWjZHQAU9QIWfpE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":608},"main":"index.js","type":"commonjs","gitHead":"cf639da4b8ee47b711fe33d90c874959e2b0900d","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"","directories":{},"_nodeVersion":"24.12.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.0.0_1776087622320_0.4895275751967594","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"dep-up-surgeon","version":"1.1.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":"","license":"ISC","_id":"dep-up-surgeon@1.1.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"b58dda23e990f5dcd3c117189bae3755aa8f0262","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.1.0.tgz","fileCount":38,"integrity":"sha512-NxY0dQ9Dh0ba3FmBTNhttW2PVCuqJGocXjjUpjZIT3uQppgExvIJ+8UelUiqsG440T1VWuKdzL6S+L9vLHDxRw==","signatures":[{"sig":"MEUCIQCSyifwciL1lWoTHs0WMkYyKZgRHll1Hk6XuXEJM0zOfgIgCsHNJs+GIGdKtmKsshqPRJfKypUyPRDOBZSSpuq2MtM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61543},"main":"dist/cli.js","type":"commonjs","types":"./dist/cli.d.ts","engines":{"node":">=18"},"gitHead":"e7a3a6bb77177d87cdf166a42168f84ea77f27c7","scripts":{"test":"echo \"No tests yet\" && exit 0","build":"tsc","start":"node dist/cli.js","prepare":"npm run build"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^4.1.2","execa":"^5.1.1","pacote":"^18.0.6","semver":"^7.6.3","prompts":"^2.4.2","fs-extra":"^11.2.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.2","@types/node":"^22.10.2","@types/semver":"^7.5.8","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.1.0_1776088237315_0.5939863750542771","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"dep-up-surgeon","version":"1.2.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":"","license":"ISC","_id":"dep-up-surgeon@1.2.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"656af5958f71afead65d54414e42543c0e7e326d","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.2.0.tgz","fileCount":42,"integrity":"sha512-qgMgDgnqAROrgRGtI5XHD5tcU9BMq5pa3vHQZHuWWUWq2nTflmEv4O09fFLxf2sE1w7nTc9oBjbbbPTdxCPS6w==","signatures":[{"sig":"MEQCIGDO9+kpPCBvv3k3ILj0+4ffsWjVBceJTJvVdyrBzVEnAiAUEZ+zGZ1/CebRMq/TV4kFT78V9uwNQAabqJlazc1aRA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":75951},"main":"dist/cli.js","type":"commonjs","types":"./dist/cli.d.ts","engines":{"node":"^18.17.0 || >=20.5.0"},"gitHead":"db9a976fd816a5f9a25cdf815b442e16b02ede32","scripts":{"test":"echo \"No tests yet\" && exit 0","build":"tsc","start":"node dist/cli.js","prepare":"npm run build"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^4.1.2","execa":"^5.1.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.2.0_1776089987283_0.1531383243594988","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"dep-up-surgeon","version":"1.3.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":"","license":"ISC","_id":"dep-up-surgeon@1.3.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"aec3398ba8e0f1976b0786aef76d9d7b570d6093","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.3.0.tgz","fileCount":42,"integrity":"sha512-wytm/D7Ft1Uz082B9zu9/uO+D7R0bVlLDH4MzsAzTvB4e1ySh9KUqmfFbuZgy2KadfgH/ItVr3Fo1JB3ruNn7A==","signatures":[{"sig":"MEUCIQCNyXHtb2IO4VdsRFq8KRU8g+68ZOhGYkxhe/TbvFec4QIgNh3tr1HSQytn3kz6eR05WONQ11xcb/KAWoLQGcI8RW4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":79525},"main":"dist/cli.js","type":"commonjs","types":"./dist/cli.d.ts","engines":{"node":"^18.17.0 || >=20.5.0"},"gitHead":"698c55d707ea32d5faf0598d3b62beccdb6212b4","scripts":{"test":"echo \"No tests yet\" && exit 0","build":"tsc","start":"node dist/cli.js","prepare":"npm run build"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"5.6.2","execa":"^5.1.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"5.9.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.3.0_1776091994398_0.7813224822740468","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"dep-up-surgeon","version":"1.4.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":"","license":"ISC","_id":"dep-up-surgeon@1.4.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"9aab23e6a57193cfcf20c66c86c637671d7c1433","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.4.0.tgz","fileCount":46,"integrity":"sha512-r3FgBA5Khhfe8PCK/EEKyLs3sTES1NkfLhcyoWn6QHn3zp1IIY8vuTVnKmhpUpfr3lC0ErCCsNN8Y25h65zNug==","signatures":[{"sig":"MEYCIQCTwo3UDEYkHNT0rhtX1bcwqpMfW6N6DSdJPcCPGNX15wIhAMe5JZpBo/EexjKfzbmdbonCpWToOGfqi2NSwpgQJHSx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":105763},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"1f9c4e2e7fef015feae8a0683e5b977284a33b1a","scripts":{"test":"echo \"No tests yet\" && exit 0","build":"tsc","start":"node dist/cli.js","prepare":"npm run build"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"5.9.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.4.0_1776092999576_0.8795307599018718","host":"s3://npm-registry-packages-npm-production"}},"1.4.1":{"name":"dep-up-surgeon","version":"1.4.1","keywords":["npm","dependencies","upgrade","cli","semver"],"author":"","license":"ISC","_id":"dep-up-surgeon@1.4.1","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"50bdf9b9f545859fd21124f981ad8302a6a0b13b","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.4.1.tgz","fileCount":46,"integrity":"sha512-pZ8AEqBa0zbYpJrDT5qufVy2p7O8GZz+qZRydzVhkGBn9V2Ga+OJ77KMNpDuTplxKuoM5c5oEYFRdm6vRmoEdA==","signatures":[{"sig":"MEYCIQDiL6M/OlMGd0zo6fQ6dr/GmVPjkuRp7CvqvTHwsq7F1AIhANxN2vyD/XJFnct5Oq0a2Mm1AENg5zMxlvf/C2LV7g7c","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":105763},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"c9016d1278bc788a90db725e3372c154b2dc193a","scripts":{"test":"echo \"No tests yet\" && exit 0","build":"tsc","start":"node dist/cli.js","prepare":"npm run build"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.4.1_1776094053785_0.7952308988880128","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"dep-up-surgeon","version":"1.5.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":"","license":"ISC","_id":"dep-up-surgeon@1.5.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"b1a0cebe60b97862e8e719036e90389a8eec6684","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.5.0.tgz","fileCount":50,"integrity":"sha512-r6R75jInr7QHt4dhDVB2twZ+NVC8j2aI77F+RPLx9WTYqQNMFOn5HoZlrv2+71k4g6tXVrNb8RVJ6P4KtgGwGw==","signatures":[{"sig":"MEUCIDgviSWbK3PKNVxnhtvwFfQYEzccmrCj8EmwLlfGVRdUAiEAofsRZOnPlrpIJFuI/dRQE5LDDL4jqO0/EsjZ2hgvbXU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":114649},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"f2c9ba7c061182c2781598a74ac374c535e7f1c2","scripts":{"test":"echo \"No tests yet\" && exit 0","build":"tsc","start":"node dist/cli.js","prepare":"npm run build"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.5.0_1776095051110_0.6620288914835322","host":"s3://npm-registry-packages-npm-production"}},"1.6.0":{"name":"dep-up-surgeon","version":"1.6.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@1.6.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"16f0b41b62e8ec11285a94cdce0cfbacd9d6e1c9","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.6.0.tgz","fileCount":86,"integrity":"sha512-gOrJsQEPxuECZXUgiO4vSyImr005/yO9c6MAeCaVeK08ZMZwn/aePlBEMD4kjVkPszPkA4SUpeUXltYR9xrVNw==","signatures":[{"sig":"MEYCIQDu0dT6CD9ePBtG4vcXi6nciruJz1pp3Wcv9wvJT+p5GAIhALq6qxUTvxX8Ews5hcll2fvWZDZAHTfK5R6RiEAe9Lv3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":176735},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"0183d006bedff4634d72ae861aac223d03d5aa7b","scripts":{"test":"echo \"No tests yet\" && exit 0","build":"tsc","start":"node dist/cli.js","prepare":"npm run build"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.6.0_1776098396778_0.4639194539464577","host":"s3://npm-registry-packages-npm-production"}},"1.6.1":{"name":"dep-up-surgeon","version":"1.6.1","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@1.6.1","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"f959b9ddfbd1a2ccab32395e809579d782ab0e0a","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.6.1.tgz","fileCount":86,"integrity":"sha512-8te+FLUwQ+5shRssjX+zH/r0zh/MWwFcyMiuz2y7NsU8KENwekw2srnY2598o0RDGV7jqXzIIl4nx1aXj8OOAQ==","signatures":[{"sig":"MEQCIAWFizp+vJw8+IRb7v546RtB7krop/6MTacd12ijjtJoAiB/IAu0mqCDapGqSTRcsv5kWhONK1VfRubnsAxZXEiBFQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":179540},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"d6c8137beb6264d6bf1cd82eeccead2d9281fea1","scripts":{"test":"echo \"No tests yet\" && exit 0","build":"tsc","start":"node dist/cli.js","prepare":"npm run build"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.6.1_1776103348221_0.37929246397090033","host":"s3://npm-registry-packages-npm-production"}},"1.6.2":{"name":"dep-up-surgeon","version":"1.6.2","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@1.6.2","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"8bc20a38117632fc93c3306763234fc208c46c1b","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.6.2.tgz","fileCount":86,"integrity":"sha512-3aamoC5SI/GtcQqhZiHe0lrGtjKASsuxgPKgwfoBO7coRbyysNKP1FH8RWFuhJ9aCl23xtI2i99ggEtdxi6nNg==","signatures":[{"sig":"MEQCICdZaw/Pa6F1S4KqYuXK/oGSJQc2QY8Q0J3UJh3aWl4FAiBfxFQ2abAOlabB4M2Xr1nCh7R1+SxzAAUkLDsPTIgpSw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":181352},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"701be153a9b35ecd08cd94b233e5b8c250270b80","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.6.2_1776357218437_0.5282566005828464","host":"s3://npm-registry-packages-npm-production"}},"1.6.3":{"name":"dep-up-surgeon","version":"1.6.3","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@1.6.3","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"2ac5be56a42fff51ad45a110a46b196d8ffe1a52","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.6.3.tgz","fileCount":86,"integrity":"sha512-8OI4a68xW5TYPUgKlnRYa4cbTvn7RgXeNSLrO02cdFs/k3mv6dRk34XEIFAb8W6vnX6e1s+bh11c6DESYaUtPg==","signatures":[{"sig":"MEQCID6ReYTcvjVCVTZ/dy6B+jq0yt8urmAXfmAQdYJSMthuAiAzZzc3y++4FuxjuMGAICCcDhbu+O0A2Sae/rwy7l7TVQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":181352},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"664a420966549a8299f52fba51f0019713295a0c","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.6.3_1776359277613_0.9120911361512034","host":"s3://npm-registry-packages-npm-production"}},"1.6.4":{"name":"dep-up-surgeon","version":"1.6.4","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@1.6.4","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"57dea04829adc715afd002e35e9bbd143410dac2","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.6.4.tgz","fileCount":86,"integrity":"sha512-FZ3epW+nfdC8kYxml9td3Ntr4umkeUJ1Q2wfYG5AYKnKJRw8zCgwMiKmyz6K2LCJjJwIxYPM/ifzU016aTx9WQ==","signatures":[{"sig":"MEYCIQD94mBiVCIUGrUH2XO41g8ai9dq8nvw7V3yMWjqu1FIfwIhAMd6K7YR2BLCQGQ0oVxkgoIHt6bh8FHfgoXt8WKGy98o","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":186747},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"4b4b2630ba2fb1d21f6e9ce3e9fa9e6223462bc1","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.6.4_1776359472909_0.6365113087996295","host":"s3://npm-registry-packages-npm-production"}},"1.6.5":{"name":"dep-up-surgeon","version":"1.6.5","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@1.6.5","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://github.com/alexlibe95/dep-up-surgeon#readme","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"cbb2d32132c11665fdd25d9f6b59e4d1f3a1f0be","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.6.5.tgz","fileCount":86,"integrity":"sha512-VWWIS5O59BVXPzMI0r0pSJHe6uXRPWDW9JtCYSk405WBvQZXUqTyWuYG1xXgbU4ZGIdN0FROAZD7Tp/EoaZpmQ==","signatures":[{"sig":"MEUCIQC7VixwbK2HHPoURGomdn8Etq/eY7QWQgLZrGFT5mfXHQIgX2yAHXSKPs92WEiYD7feRz82kbf4qbp0E460W1W0lBY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":186369},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"197d4e4cf5b77c66af0556fe3b0f5c5d09c742d3","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.6.5_1776359895357_0.46421964574854235","host":"s3://npm-registry-packages-npm-production"}},"1.6.6":{"name":"dep-up-surgeon","version":"1.6.6","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@1.6.6","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"b40c6b8e59b6034face2215ce821b124e0146f00","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-1.6.6.tgz","fileCount":86,"integrity":"sha512-Zhn0evQrWdQBMPWuCOAKI7mXxnUXrLEW57QxhtghMtVC7TbLXtcyvPZCILxZqxDWbryNEdutmg0TuwuH0206Pw==","signatures":[{"sig":"MEQCIAMhv1w6ufetjAagW5ZAJy/BMwA7lJDplmCBr0VCAhiyAiA65HPiXrl35cGerPNxZRZiFjuqiDZvUweYOFSpQiGt3g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":186806},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"6b72278c17cc17796e508e8aa45dca1aef5a4aca","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_1.6.6_1776495255237_0.4296602998005752","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"dep-up-surgeon","version":"2.0.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.0.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"22bc8e048f36389f804bde6a315b0d3a27e07840","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.0.0.tgz","fileCount":110,"integrity":"sha512-MvKMoEz7OIBT4vWnckSi0/ZTRuRhNd0m9er9CuQZpZMRvqnBELlRV3d6iR1dsZ5vNL8AjhZwO13eo0VbueO8gg==","signatures":[{"sig":"MEUCIB2Dq38GzLsuixoqFalsjF+FSETufpHMwravsC3AT+1gAiEA6T93rC3XOGkfj5eyhik04Hc3FfQoPDRDc5E6OqXlQSY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":432563},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"a55b6193a9dbb714711829a3bcde86d28886f369","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.2","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.0.0_1776538150320_0.6273023746912949","host":"s3://npm-registry-packages-npm-production"}},"2.1.0":{"name":"dep-up-surgeon","version":"2.1.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.1.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"8b1ce1181f383e3819b27000e85d4c70323b0dc0","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.1.0.tgz","fileCount":130,"integrity":"sha512-SyqHY52jKPCMG/YJgTSFi9S2rKswLRjr/DqFejlU6+Z54it10hKCF+Xig6t02ZFVaz1DhaPxmlmlqjQesjWycg==","signatures":[{"sig":"MEUCIDX3yh2Yx0Wvd/j0VlV24IJj0WHiwiGTxgwBE+ljAERnAiEAmX5lORJv+E3b5j9erbgnzs7/VIGc10QEpshM9l2gAPw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":611328},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"f66267ac28b02677c08f966da7c3379a801dad95","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.1.0_1776675767835_0.741837307984943","host":"s3://npm-registry-packages-npm-production"}},"2.2.0":{"name":"dep-up-surgeon","version":"2.2.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"a431f18b35ff49c369d11b9a6282dcefe8b97112","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.0.tgz","fileCount":142,"integrity":"sha512-TPiuLIROOxLP2NZEpHGDq1IteUm1Tpyp87t93Z5c5FQBv/XimDHs3ZDWl14apikS32bRf7OqM8gLO1FKL8LPmA==","signatures":[{"sig":"MEUCIQCWQNNPT5IETaZZkhS6PblNN+YTDlVGokOwl5C66yCQZwIgLTStTlgFu/CNr676LyLMEKF7cGkVKzILJiLGnakzwdk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":730559},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"8dd97132e199df01d6dd3191b843d6628253b3dd","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.0_1776677104138_0.45750812921972717","host":"s3://npm-registry-packages-npm-production"}},"2.2.1":{"name":"dep-up-surgeon","version":"2.2.1","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.1","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"28caf184d2cc32eb69c2dec648898405fbd62c7c","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.1.tgz","fileCount":150,"integrity":"sha512-GEsGI5w1dRBX+qAcOkZ5OKqlN6OWJRIwoqSM06sqJEthSD8FyEy+BOEW8gpnD9YeiiBgCSKGl6ZKh/oP+jAkPQ==","signatures":[{"sig":"MEYCIQC/R+4uOXTQCz0+mDu1ERH/wqWbtpqD3UVqhxmPOHYYrAIhAOIdSnkG3pPHPRzDqK+33I8ZquoaqGJR9xUOLopYQzzi","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":851059},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"5607630e19d4f022471cfcd944ef0931e69fcd42","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/peer-resolver.test.mjs test/unit/lockfile-fix.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/peer-resolver.test.mjs test/unit/lockfile-fix.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.1_1776683945375_0.6179899411608571","host":"s3://npm-registry-packages-npm-production"}},"2.2.2":{"name":"dep-up-surgeon","version":"2.2.2","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.2","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"c1f90869c8414035ce5c94773714d1f61f734bcd","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.2.tgz","fileCount":162,"integrity":"sha512-XPYzrgdzp8qnj9z/0ZvRu6/jSny0jjGEBGyQuotl65QTpOjP4TFjwC2yVhZmVOKNFZWo7QiT6WN7v1PVmDMLRg==","signatures":[{"sig":"MEQCIDO232/vEAzCnldbE8kF5vNoRzUNx7y0brGdkEz+j+QKAiBO6iZcL6qRJxIuUhFIABSj0qZGT4L1Vl2g3WqnkKE/QQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":934775},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"62290a271c493d5f89e55a4b38855e6b375be52c","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/peer-resolver.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/peer-resolver.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.2_1776686434391_0.4461896669515615","host":"s3://npm-registry-packages-npm-production"}},"2.2.3":{"name":"dep-up-surgeon","version":"2.2.3","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.3","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"9896a120bd08929a95e50ff8ae7d33e4edb7bdb1","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.3.tgz","fileCount":166,"integrity":"sha512-DrAECWku0aJUoDwmPG521bO4tuiyHxZj/+KdTwlnzT5QL4qQoCbo6v0hXwTZS5XyJh8PdS3FPMBdouWp+C0B+g==","signatures":[{"sig":"MEQCIFEtstdP25B0McA7ozNWKaOi/HvHJ+l+/gIN6mTknUaUAiAaYxxMqEHs7bvRzZXE5eQVohuljiH84lq7awozimUYyg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1035284},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"985b4ca1b22afae7865d4ed5a40bb382dbda6a0e","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.3_1776694580942_0.5240520057248255","host":"s3://npm-registry-packages-npm-production"}},"2.2.4":{"name":"dep-up-surgeon","version":"2.2.4","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.4","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"aa54f9117d3a878b4f7052afa64117013934aa0e","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.4.tgz","fileCount":174,"integrity":"sha512-/XyYTsNwajHt6BwM5tX+G0Paum1jiX7VZ4VUpGa6U5LJ6/BnC3PZzqUgo55GsYxNWYCAf/IHCr1gZX04ac8lAg==","signatures":[{"sig":"MEQCIBIeUx0tMFT8QavQDJ/PdG0bR4H0O/MPbIL108Ddy+7AAiBPAqlkJOgOjtOClgk9a5zXAH3NTnSRT78lSRPs556A8g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1110263},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"8d1c462b229febeb22de4a30523370bcff58aa15","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.4_1776704839822_0.3560087110659862","host":"s3://npm-registry-packages-npm-production"}},"2.2.5":{"name":"dep-up-surgeon","version":"2.2.5","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.5","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"3d69e84b2ef41c7fe2881407b205ac43e8763e8e","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.5.tgz","fileCount":174,"integrity":"sha512-EPm3Z8y07jHpLsTvRW3G9TuuHAF0jsYTVkL48DRXZ4FfdCsAe68xl2J4GDRfwzXWKePgkK2/cEEXnvq3RzwzpQ==","signatures":[{"sig":"MEQCICQrlJRUyBE9h2MxWdx3YCcCfOkw+E0EnfHDH5vhrMjAAiBCLFRZhgYie+pwFtnvOJKF8E936HZBGS/V5t+XaN5jdA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1129269},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"b34a9d14751edf3034079eedbda0c55df26cddca","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.5_1776877720164_0.16343381188778872","host":"s3://npm-registry-packages-npm-production"}},"2.2.6":{"name":"dep-up-surgeon","version":"2.2.6","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.6","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"00bb008de4a6f541732ebad087d6ed394028d930","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.6.tgz","fileCount":174,"integrity":"sha512-sdrQnTwpfJy1WTGZP31J2WYBHoSybdlxF0yIVrt2/finxHwlhGY/Ek2sCWSTOjrRwTyQ5WOuiFBmoa0N9CPmmA==","signatures":[{"sig":"MEUCICnGyUjJ3vin5qyJ2gFLjrkQQfV2xz9NrhSd9v+sxgbKAiEA0e/Uzo/B2xeVjPuig5IkN/cKiR1xHNHPtqPT9KM4WrI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1138510},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"6b724b0226ba3bb3328094e5b0b4a13d91e564ff","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.6_1777067157168_0.11256000046311265","host":"s3://npm-registry-packages-npm-production"}},"2.2.7":{"name":"dep-up-surgeon","version":"2.2.7","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.7","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"c392d953a85fe368188a624233815f86dc862990","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.7.tgz","fileCount":174,"integrity":"sha512-AP2zHLyVbrBg77nQxhqBnuJR83gOihXdQj3+sIoD2c1wEvkUORUHySM4eBYho72j62RztrMDV42aocBpJVGcYw==","signatures":[{"sig":"MEUCIQDtC65SEFX9cDCvWLE3xEqLURVy/YK1b850a+Lvg00v6gIgHARt6MhwOYAcEi3DatqvbvkkZBWFfZnPNyaGtil1nAk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1143603},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"480e5e3ee2df14e2c18a1dd3560d3f0614d7bc10","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.7_1777067721410_0.416409277687561","host":"s3://npm-registry-packages-npm-production"}},"2.2.8":{"name":"dep-up-surgeon","version":"2.2.8","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.8","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"132a417e5088dafcacb15bef575f1138ef5ddc5d","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.8.tgz","fileCount":174,"integrity":"sha512-Ecd5ezE+iVDt87D90TCtzCHOvTjt3lgwXi/TDMKMdQMmKaiUyInEuS3LWkUXAIlRu270uofAiQQFhTk+DJlh6g==","signatures":[{"sig":"MEUCIHx54arWjd9k9D4jiVwIm9kEyxt/R9EyYt+9bKpkukNcAiEAjohdzZ9IRXP0Tj4rmeTCPXqe50KkP+3qzhMj2uBq5Gw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1146152},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"97a67c8d7f99fd7f30e079395f6b8e25483adab2","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.0","semver":"7.7.4","prompts":"^2.4.2","fs-extra":"11.3.4","commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"6.0.3","@types/node":"25.6.0","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.8_1777068599680_0.9110241277349871","host":"s3://npm-registry-packages-npm-production"}},"2.2.9":{"name":"dep-up-surgeon","version":"2.2.9","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.2.9","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"1942ee473cd70d6acb23719f64e91ec53051d41e","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.2.9.tgz","fileCount":174,"integrity":"sha512-SxDLru9yL4cXZCvKdYJkFxL3zApC5eZFCEJ3x0DDzd56J7p2FtPca5pKjWLQqmWDh174OaJh9Dj1jKh9Gpo2qg==","signatures":[{"sig":"MEUCIQDOhQ79cZ7tILyCDMH/i9+y4/hGjlQN0E330oZPFFzibgIgc3Dyk1F6+d6FrhPcr31d3/detvqafDouL8JEgc5dw1w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1146279},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"2686b3f9099ca616b8fe5c13a5fe12422c44e755","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.9.0","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.1","semver":"7.8.5","prompts":"^2.4.2","fs-extra":"11.3.6","commander":"^15.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"7.0.2","@types/node":"26.1.1","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.2.9_1783885860621_0.6364331508833845","host":"s3://npm-registry-packages-npm-production"}},"2.3.0":{"name":"dep-up-surgeon","version":"2.3.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.3.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"a7cde4e0e479a8667499cb03b9edd92d2e2ed342","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.3.0.tgz","fileCount":194,"integrity":"sha512-mpJX4XmUEQej91NeqrxrjX+mgQG5yJgVTLHW3G97GHGsKKDvSCgWq+vKuMvZXn0FOO/1HE/Foox99gmPCdva9A==","signatures":[{"sig":"MEQCIFZ7AmIafYRZEnOxw9U/Nd9TCLokj3EzIrGVt5621IgwAiAdtvDE4RynaAqYrBo6cBDJXmgZ99feN1U5GQu0FPVhTw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1194531},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^20.17.0 || >=22.9.0"},"gitHead":"b1516bb4e1fbdba2e4a8f63ddfec87b970bf71e0","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/unit/range-style.test.mjs test/unit/installed-version.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/unit/range-style.test.mjs test/unit/installed-version.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.6.2","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.9.0","chalk":"^5.6.2","execa":"^9.6.1","pacote":"21.5.1","semver":"7.8.5","prompts":"^2.4.2","fs-extra":"11.3.6","commander":"^15.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"7.0.2","@types/node":"26.1.1","@types/semver":"7.7.1","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.3.0_1784626766141_0.49095033134874555","host":"s3://npm-registry-packages-npm-production"}},"2.4.0":{"name":"dep-up-surgeon","version":"2.4.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@2.4.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"8a8b6b0a72bbe71d1bc6c587cb4e5b8f7bef08f1","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-2.4.0.tgz","fileCount":203,"integrity":"sha512-+H8WpkyaU0tu5U6lfgoFbxljSI+irb4pjYXhEIdmIBzofSXds7tZ0OE+HM8gRjvUQRVeYOuHuorZlMsPovPh5Q==","signatures":[{"sig":"MEUCIHOX9m9cThVFHgmH8kpK6fVyonM5fhhPUgomz/HHnPaFAiEAufbLG72Eg2XKesMBIgY7DLB9XlISmvNcyJX0HNH/Dwc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1251405},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"gitHead":"dbabd9f5b62c3ddeed363d4ef47d0111777b2d7e","scripts":{"test":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/unit/range-style.test.mjs test/unit/installed-version.test.mjs test/unit/catalog.test.mjs test/fixtures-runner.mjs","build":"tsc","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test test/unit/conflict-parser.test.mjs test/unit/npm-output-samples.test.mjs test/unit/workspaces.test.mjs test/unit/output-tail.test.mjs test/unit/upgrade-flow-targets.test.mjs test/unit/last-run-retry.test.mjs test/unit/summary.test.mjs test/unit/install-filter.test.mjs test/unit/concurrency.test.mjs test/unit/git.test.mjs test/unit/changelog.test.mjs test/unit/audit.test.mjs test/unit/policy.test.mjs test/unit/blast-radius.test.mjs test/unit/breaking-changes.test.mjs test/unit/open-pr.test.mjs test/unit/overrides.test.mjs test/unit/override-flow.test.mjs test/unit/rc-overrides.test.mjs test/unit/undo.test.mjs test/unit/peer-resolver.test.mjs test/unit/peer-resolver-adhoc.test.mjs test/unit/lockfile-fix.test.mjs test/unit/doctor.test.mjs test/unit/security-only.test.mjs test/unit/range-style.test.mjs test/unit/installed-version.test.mjs test/unit/catalog.test.mjs","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.17.0","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"yaml":"^2.9.0","chalk":"^6.0.0","execa":"^10.0.1","pacote":"22.0.0","semver":"7.8.5","prompts":"^2.4.2","fs-extra":"11.4.0","commander":"^15.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"7.0.2","@types/node":"26.2.0","@types/semver":"7.8.0","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_2.4.0_1786882609535_0.3367413205066494","host":"s3://npm-registry-packages-npm-production"}},"3.0.0":{"name":"dep-up-surgeon","version":"3.0.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@3.0.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"506b8529d8df9c302b26a03148acc1ac9ebbc065","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-3.0.0.tgz","fileCount":203,"integrity":"sha512-ZHYlQuwgNsdJKIi0iNn6jQDQ7Izfuby4ZSrTheeWwz0z+qAbiDgZep6B+zOlKKChCW/0AKvTzBnKocRAJNi5YQ==","signatures":[{"sig":"MEYCIQCbgZxKmPk69fp6QGSNdqCoXLQfLXHHOWKLwAN0d09SsAIhAKEzMipi0VJSAMsC+1A2ZtpKzkA6bzg2VX9enCJlccXQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1394071},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"gitHead":"762c677733f13349e2988908900a9dc813319aa4","scripts":{"test":"npm run build && node --test \"test/unit/*.test.mjs\" test/fixtures-runner.mjs","build":"npm run clean && tsc","clean":"node -e \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test \"test/unit/*.test.mjs\"","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.19.0","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.21.0","dependencies":{"yaml":"^2.9.1","chalk":"^6.0.0","execa":"^10.0.1","pacote":"22.0.0","semver":"7.8.5","prompts":"^2.4.2","fs-extra":"11.4.0","commander":"^15.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"7.0.2","@types/node":"26.5.1","@types/semver":"7.8.0","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_3.0.0_1789172850488_0.6879351738193371","host":"s3://npm-registry-packages-npm-production"}},"4.0.0":{"name":"dep-up-surgeon","version":"4.0.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@4.0.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"0e79c0c073bfaabf0f844481b1092036cdf8a497","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-4.0.0.tgz","fileCount":211,"integrity":"sha512-5TGMKyvcje590sbLc2Jvjw8vpQ6wpGb3QxBg7g003yYTZ+enLD2W2FzsBom5GAa4XOVn2+mBIymeZHTgsQ+BBA==","signatures":[{"sig":"MEUCIBKroE/VcjWYH93GNb3G5Bh82Xu/pUig1CZPdENuXdXeAiEAnj7LyxmAW8Q+5Wt0MjbqZzeBK10yYrPs3nPnBvmhVrU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1465386},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"gitHead":"f373c761b70fc7c16358de894bb21ced065ca98b","scripts":{"test":"npm run build && node --test \"test/unit/*.test.mjs\" test/fixtures-runner.mjs","build":"npm run clean && tsc","clean":"node -e \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test \"test/unit/*.test.mjs\"","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.19.0","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.21.0","dependencies":{"yaml":"^2.9.1","chalk":"^6.0.0","execa":"^10.0.1","pacote":"22.0.0","semver":"7.8.5","prompts":"^2.4.2","fs-extra":"11.4.0","commander":"^15.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"7.0.2","@types/node":"26.5.1","@types/semver":"7.8.0","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_4.0.0_1789327115968_0.8056384504773433","host":"s3://npm-registry-packages-npm-production"}},"4.1.0":{"name":"dep-up-surgeon","version":"4.1.0","keywords":["npm","dependencies","upgrade","cli","semver"],"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","_id":"dep-up-surgeon@4.1.0","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"homepage":"https://dep-up-surgeon.netlify.app/","bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"bin":{"dep-up-surgeon":"dist/cli.js"},"dist":{"shasum":"17b14a68ec2eb1f0fafcffe6f632b1b826a05d42","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-4.1.0.tgz","fileCount":215,"integrity":"sha512-Cd1Gil6+9MdfTePSRCEwN5q28XPQdVLL5n3r1mo2Rpw+E7kphcia0Tv1pqBUtwdf6mYZC9eGPIXSby/SLAJXJA==","signatures":[{"sig":"MEYCIQCUkr0vbUv1KYcDYp7FPOV6XP2v+lBTPsKBO19ZFpUNAgIhAM1ES0fYP35DMOrJlDCmLd0dmkpU3ykgeB/GaGbpGfsC","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIHW8WBDn/nP5jhf22e7Gq5P6v60JXEG6GT5+kM82BIyeAiAPXZwn3gVEr/a0ePRWPHbOrBfdkBlvXWLjqZ/BByrt3w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1491946},"main":"dist/cli.js","type":"module","types":"./dist/cli.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"gitHead":"4f6d20b625c0d1dc5ed58d45e8c5093462355b52","scripts":{"test":"npm run build && node --test \"test/unit/*.test.mjs\" test/fixtures-runner.mjs","build":"npm run clean && tsc","clean":"node -e \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test \"test/unit/*.test.mjs\"","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.19.0","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"_nodeVersion":"24.21.0","dependencies":{"yaml":"^2.9.1","chalk":"^6.0.0","execa":"^10.0.1","pacote":"22.0.0","semver":"7.8.5","prompts":"^2.4.2","fs-extra":"11.4.0","commander":"^15.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"7.0.2","@types/node":"26.5.1","@types/semver":"7.8.0","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"tmp":"tmp/dep-up-surgeon_4.1.0_1789668993978_0.8061361440385435","host":"s3://npm-registry-packages-npm-production"}},"4.1.1":{"_id":"dep-up-surgeon@4.1.1","bin":{"dep-up-surgeon":"dist/cli.js"},"bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"dist":{"shasum":"ae4c290b93aeb5466c42d621467574d6668b793b","tarball":"https://registry.npmjs.org/dep-up-surgeon/-/dep-up-surgeon-4.1.1.tgz","fileCount":215,"integrity":"sha512-eWZ1CU6f6qAcsgblRDvM7hWVgmPVOAKgmc3MbcoDUlqJIn9wQPe0PM/wmCQVms/7a5+saPfN5EMLlSYyMV/1tQ==","signatures":[{"sig":"MEQCIFNa5PamrJ+cqFmOk/sc00+aMX4pWXIzw9lHJD4arc+OAiA46eLwvtu1j4SIPJiNn+tooAlgtJo2I/yxsv7uvxUOgQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIC4gaAbgRhlzTCaP//imTCm9kh7PUvVtEBe2L5agqTQRAiBIOh2R/zlkGWmQSWIXPkX2idXIqLoG0umRHjHWQ0CeFA=="}],"unpackedSize":1491946},"main":"dist/cli.js","name":"dep-up-surgeon","type":"module","types":"./dist/cli.d.ts","author":{"name":"Alexandros Lymperopoulos"},"engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"gitHead":"bc55bb05487517ef1b812776fdaeeb0300865bf1","license":"ISC","scripts":{"test":"npm run build && node --test \"test/unit/*.test.mjs\" test/fixtures-runner.mjs","build":"npm run clean && tsc","clean":"node -e \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","start":"node dist/cli.js","prepare":"npm run build","test:unit":"npm run build && node --test \"test/unit/*.test.mjs\"","test:fixtures":"npm run build && node --test test/fixtures-runner.mjs"},"version":"4.1.1","_npmUser":{"name":"alexnpm95","email":"alexlibe95@gmail.com"},"homepage":"https://dep-up-surgeon.netlify.app/","keywords":["npm","dependencies","upgrade","cli","semver"],"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"_npmVersion":"11.19.0","description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","directories":{},"maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"_nodeVersion":"24.21.0","dependencies":{"yaml":"^2.9.1","chalk":"^6.0.0","execa":"^10.0.1","pacote":"22.0.0","semver":"7.8.5","prompts":"^2.4.2","fs-extra":"11.4.0","commander":"^15.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"7.0.2","@types/node":"26.6.1","@types/semver":"7.8.0","@types/prompts":"^2.4.9","@types/fs-extra":"^11.0.4"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dep-up-surgeon_4.1.1_1789772982786_0.7009491455892498"}}},"time":{"created":"2026-04-13T13:40:22.319Z","modified":"2026-09-18T23:09:43.093Z","1.0.0":"2026-04-13T13:40:22.440Z","1.1.0":"2026-04-13T13:50:37.454Z","1.2.0":"2026-04-13T14:19:47.449Z","1.3.0":"2026-04-13T14:53:14.528Z","1.4.0":"2026-04-13T15:09:59.722Z","1.4.1":"2026-04-13T15:27:33.903Z","1.5.0":"2026-04-13T15:44:11.335Z","1.6.0":"2026-04-13T16:39:56.921Z","1.6.1":"2026-04-13T18:02:28.366Z","1.6.2":"2026-04-16T16:33:38.592Z","1.6.3":"2026-04-16T17:07:57.740Z","1.6.4":"2026-04-16T17:11:13.064Z","1.6.5":"2026-04-16T17:18:15.503Z","1.6.6":"2026-04-18T06:54:15.409Z","2.0.0":"2026-04-18T18:49:10.507Z","2.1.0":"2026-04-20T09:02:47.972Z","2.2.0":"2026-04-20T09:25:04.337Z","2.2.1":"2026-04-20T11:19:05.546Z","2.2.2":"2026-04-20T12:00:34.569Z","2.2.3":"2026-04-20T14:16:21.093Z","2.2.4":"2026-04-20T17:07:20.046Z","2.2.5":"2026-04-22T17:08:40.320Z","2.2.6":"2026-04-24T21:45:57.346Z","2.2.7":"2026-04-24T21:55:21.585Z","2.2.8":"2026-04-24T22:09:59.945Z","2.2.9":"2026-07-12T19:51:00.902Z","2.3.0":"2026-07-21T09:39:26.331Z","2.4.0":"2026-08-16T12:16:49.688Z","3.0.0":"2026-09-12T00:27:30.663Z","4.0.0":"2026-09-13T19:18:36.133Z","4.1.0":"2026-09-17T18:16:34.075Z","4.1.1":"2026-09-18T23:09:42.930Z"},"bugs":{"url":"https://github.com/alexlibe95/dep-up-surgeon/issues"},"author":{"name":"Alexandros Lymperopoulos"},"license":"ISC","homepage":"https://dep-up-surgeon.netlify.app/","keywords":["npm","dependencies","upgrade","cli","semver"],"repository":{"url":"git+https://github.com/alexlibe95/dep-up-surgeon.git","type":"git"},"description":"Upgrade npm dependencies one-by-one with validation, rollback, and conflict reporting.","maintainers":[{"name":"alexnpm95","email":"alexlibe95@gmail.com"}],"readme":"# dep-up-surgeon\n\n[![CI](https://github.com/alexlibe95/dep-up-surgeon/actions/workflows/ci.yml/badge.svg)](https://github.com/alexlibe95/dep-up-surgeon/actions/workflows/ci.yml)\n[![npm version](https://img.shields.io/npm/v/dep-up-surgeon.svg)](https://www.npmjs.com/package/dep-up-surgeon)\n[![npm downloads](https://img.shields.io/npm/dm/dep-up-surgeon.svg)](https://www.npmjs.com/package/dep-up-surgeon)\n[![npm license](https://img.shields.io/npm/l/dep-up-surgeon.svg)](https://www.npmjs.com/package/dep-up-surgeon)\n[![npm unpacked size](https://img.shields.io/npm/unpacked-size/dep-up-surgeon.svg)](https://www.npmjs.com/package/dep-up-surgeon)\n[![Node.js engines](https://img.shields.io/node/v/dep-up-surgeon.svg)](https://github.com/alexlibe95/dep-up-surgeon/blob/main/package.json)\n[![TypeScript](https://img.shields.io/badge/TypeScript-7.x-3178c6?logo=typescript&logoColor=white)](https://github.com/alexlibe95/dep-up-surgeon)\n[![GitHub stars](https://img.shields.io/github/stars/alexlibe95/dep-up-surgeon?style=social)](https://github.com/alexlibe95/dep-up-surgeon)\n[![GitHub forks](https://img.shields.io/github/forks/alexlibe95/dep-up-surgeon?style=social)](https://github.com/alexlibe95/dep-up-surgeon)\n[![GitHub issues](https://img.shields.io/github/issues/alexlibe95/dep-up-surgeon.svg)](https://github.com/alexlibe95/dep-up-surgeon/issues)\n[![GitHub pull requests](https://img.shields.io/github/issues-pr/alexlibe95/dep-up-surgeon.svg)](https://github.com/alexlibe95/dep-up-surgeon/pulls)\n[![GitHub contributors](https://img.shields.io/github/contributors/alexlibe95/dep-up-surgeon.svg)](https://github.com/alexlibe95/dep-up-surgeon/graphs/contributors)\n[![Last commit](https://img.shields.io/github/last-commit/alexlibe95/dep-up-surgeon/main.svg)](https://github.com/alexlibe95/dep-up-surgeon/commits/main)\n[![Commit activity](https://img.shields.io/github/commit-activity/m/alexlibe95/dep-up-surgeon.svg)](https://github.com/alexlibe95/dep-up-surgeon/graphs/commit-activity)\n[![Libraries.io release](https://img.shields.io/librariesio/release/npm/dep-up-surgeon.svg)](https://libraries.io/npm/dep-up-surgeon)\n[![Libraries.io dependents](https://img.shields.io/librariesio/dependents/npm/dep-up-surgeon.svg)](https://libraries.io/npm/dep-up-surgeon)\n[![Website](https://img.shields.io/website?url=https%3A%2F%2Fdep-up-surgeon.netlify.app%2F&label=website)](https://dep-up-surgeon.netlify.app/)\n\n**Website:** [https://dep-up-surgeon.netlify.app/](https://dep-up-surgeon.netlify.app/)\n\nProduction-oriented CLI that upgrades **npm** dependencies with **`npm install` + validation** after each change, and **rolls back** on failure. It is **framework-agnostic**: grouping and conflict handling come from **registry metadata** and **parsed npm output**, not hardcoded stacks (React, Angular, etc.).\n\n## Install\n\n```bash\nnpm install -g dep-up-surgeon\n```\n\nOr run locally after cloning:\n\n```bash\nnpm install\nnpm run build\nnpx dep-up-surgeon --help\n```\n\n## What's new in 4.1\n\n- **A failed linked group no longer drops its safe members.** When the whole group fails, the members that jump to a new major are held back and the rest upgrade on their own (e.g. an `eslint-config-next` patch lands while `eslint@10` is reported as failed). See **When a linked group can't move as a whole**. Consumers that key on `[group:<id>]` rows: a held-back member is now reported as a plain row with `linkedGroupId`.\n- **A lagging `latest` dist-tag no longer hides updates.** When the installed version is newer than the tag, the newest release of the installed major is used (`@types/node` 26.5.1 → 26.6.1 while `latest` pointed at 22.20.3); `outdated` reports it with `latestTag`.\n- **Peer hold-backs name their blocker** (`skipped[].blockedBy`), and a resolver tuple equal to what's installed is no longer installed and validated again. `failed[].requestedLatest` records the version each failure was aiming for.\n- **`--progress`** keeps the progress lines on stderr together with `--json`, for tools that show a live log next to the report.\n\n## Upgrading from 3.x\n\n4.0 changes a few defaults — check these if you run dep-up-surgeon in CI:\n\n- **Run state moved** from `.dep-up-surgeon.last-run.json` in the project root to `node_modules/.cache/dep-up-surgeon/` (`last-run.json` + `last-run.<lockfile>`), so a run leaves only `package.json` and the lockfile changed. Root reports from older versions are still read by `undo` / `--retry-failed`; cache or upload the new directory instead of the old file.\n- **Validation is stricter.** The default validator also runs your `lint` / `typecheck` / `type-check` scripts (see **Pre-flight check**), and every install is followed by a peer-range check between installed direct dependencies (see **Conflict detection**). Expect rollbacks — and exit `1` — where 3.x kept an upgrade that broke linting or left the tree uninstallable.\n- **Files the run rewrites are restored.** Tracked files other than dependency files that change during the run (e.g. `tsconfig.json` rewritten by `next build`) are checked out again at the end.\n\n## Usage\n\nFrom your project root (where `package.json` lives):\n\n```bash\ndep-up-surgeon [options]\ndep-up-surgeon doctor [options]\ndep-up-surgeon undo [options]\ndep-up-surgeon outdated [options]\n```\n\n### Options\n\n| Option | Description |\n|--------|-------------|\n| `--dry-run` | Resolve latest versions and print the plan; does not change `package.json` or run installs. |\n| `--interactive` | On failure, prompts for next steps (see **Interactive mode**). After the run, optionally bulk-add failed names to `.dep-up-surgeonrc`. |\n| `--force` | Keep a version bump even when validation fails; also skips **rollback** when structured conflicts are detected in npm output after a successful exit code (use with care). |\n| `--ignore <pkgs>` | Comma-separated **package names** to skip in **every** workspace (merged with `.dep-up-surgeonrc`). This is global by name — unlike `--retry-failed`, which freezes per workspace. |\n| `--json` | Machine-readable report on stdout (see **JSON report**). Warnings and errors go to stderr, so stdout is always valid JSON. Progress lines are off unless `--progress` is added. |\n| `--progress` | With `--json`, still print progress (installs, validation, rollbacks, the lines of **Live progress**) to **stderr**; stdout keeps only the JSON report. For tools that show a live log next to the report (e.g. PumpBar). Parallel `--concurrency` drops to `1` so the lines stay readable. |\n| `--fallback-strategy <mode>` | `major-lines` (**default**), `minor-lines`, or `none`. After `@latest` fails, **`major-lines`** tries the best stable version per **major** (e.g. `9.x` → `8.x` → `7.x` …). **`minor-lines`** steps one **`major.minor` line** at a time. If npm output looks like **ESM vs CommonJS** (`ERR_REQUIRE_ESM`), further fallbacks for that package **stop**. `none` only attempts `@latest`. For **linked groups**, members step back together, and when the whole group still fails the members that jump to a new major are held back while the rest upgrade on their own (see **When a linked group can't move as a whole**); `none` turns both off. |\n| `--link-groups <mode>` | `auto` (**default**) or `none`. **`auto`** builds **linked batches** from the registry graph and optional **`linkedGroups`**. **`none`** upgrades one dependency per step. |\n| `--validate <cmd>` | Override the validator command run after every install. Defaults to `<manager> test` if a `test` script exists, else `<manager> run build` (yarn classic uses `yarn build`), else nothing — plus any `lint` / `typecheck` / `type-check` script, guarded by its pre-flight exit code (see **Pre-flight check**). Useful in monorepos where the default build is heavy or fragile (e.g. `--validate \"tsc -p tsconfig.json --noEmit\"`). |\n| `--no-validate` | Skip validation entirely. Upgrades are kept regardless of test/build outcome. Different from `--force`: `--force` runs the validator and only keeps the bump when it fails, `--no-validate` doesn’t run a validator at all. |\n| `--package-manager <mgr>` | `auto` (**default**), `npm`, `pnpm`, `yarn`, or `bun`. `auto` reads the `packageManager` field, then falls back to lockfile detection (`pnpm-lock.yaml` → pnpm, `yarn.lock` → yarn, `bun.lock` / `bun.lockb` → bun, `package-lock.json` → npm), then `pnpm-workspace.yaml`, then `npm`. The chosen manager drives both the **install** command (`<mgr> install`) and the **default validator** (`<mgr> test` / `<mgr> run build`; bun uses `bun run test` / `bun run build`). |\n| `--cwd <path>` | Run against this directory instead of `process.cwd()`. Default is still the current working directory, so scripts that `cd` first keep working. Same flag as `doctor` / `undo` / `outdated`. |\n| `--include-workspace-deps` | By default, dependencies whose name matches a local **workspace package** (resolved via `workspaces` in `package.json` or `pnpm-workspace.yaml`) are skipped — their version comes from the local workspace, not the registry. Pass this flag to upgrade them anyway (e.g. when local workspace packages also publish to the registry). |\n| `--include-peers` | Also upgrade `peerDependencies` entries. Default: skip peers (they are a consumer contract; auto-bumping them is usually wrong for libraries). |\n| `--pin-exact` | Write bare exact versions (`1.2.3`) into `package.json` instead of preserving the previous `^` / `~` range style. |\n| `--workspaces` | Traverse the **root** `package.json` **and every workspace member** (one engine pass per `package.json`). Install + validation always run from the workspace root so the lockfile and validator see the whole monorepo. |\n| `--workspaces-only` | Like `--workspaces` but **skips** the root `package.json`. Only workspace members are traversed. |\n| `--workspace <names>` | Comma-separated workspace member **names** (the `name` field from each child `package.json`) to traverse. Pass `root` to also include the root. Example: `--workspace \"@org/core,@org/web,root\"`. Unknown names produce a friendly error listing the known members. |\n| `--install-mode <mode>` | Workspace install strategy. **`root`** (default) always runs `<mgr> install` from the workspace root after every mutation — the safest option, supported by every package manager. **`filtered`** rewrites per-child installs to their workspace-scoped form: **npm 7+** uses `npm install --workspace <name>`, **pnpm** / **bun** use `<mgr> install --filter <name>`, **yarn berry (v2+) with `@yarnpkg/plugin-workspace-tools`** uses `yarn workspaces focus <name>`, and **yarn classic / berry without the plugin** falls back to a full root install with a one-time warning explaining the upgrade path. The capability is auto-detected at startup (yarn version + plugin probe) and reported as `project.yarnMajorVersion` + `project.yarnSupportsFocus` in `--json`. Only meaningful with `--workspaces` / `--workspaces-only` / `--workspace <names>`. |\n| `--concurrency <n>` | Maximum number of workspace targets to traverse in parallel (1–16; default `1`). Higher values overlap registry **scan + plan** phases across targets while a shared mutex keeps **install + validation strictly serialized** — the workspace lockfile is shared, so concurrent installs would corrupt it. The default in-process registry cache also deduplicates `pacote.manifest` / `pacote.packument` calls across targets, so even at concurrency `1` you get a speedup when the same dep appears in many workspaces. **Requires `--json`** so per-target log lines don't interleave; non-JSON mode silently downgrades to `1` with a warning. In an **isolated-lockfile** monorepo (pnpm `shared-workspace-lockfile=false`, or every workspace member shipping its own lockfile) installs + validation are ALSO run in parallel — see **Parallel installs** below. |\n| `--no-parallel-installs` | Force installs + validation to stay serialized even when an isolated-lockfile monorepo is detected. Useful when debugging a flaky install step (parallel installs mask the ordering) or when a per-workspace postinstall script touches shared state outside its workspace. |\n| `--retry-failed` | Resume the previous run from its last-run report (`node_modules/.cache/dep-up-surgeon/last-run.json`): freeze last-run successes and terminal failures (`peer`, `validation-script`) **per workspace**, and re-attempt only non-terminal residue (`install`, `validation-conflicts`, `versions`, `unknown`). User `--ignore` / rc lists stay global. See **Retry-failed mode** below. |\n| `--no-persist-report` | Do **not** write the last-run report after the run. By default it is written to `node_modules/.cache/dep-up-surgeon/last-run.json` (with pre-run lockfile backups) for `undo`, `--retry-failed` and CI consumers. |\n| `--summary <format>` | Write a human-friendly summary of the run as `md` (default) or `html`. Destination is `$GITHUB_STEP_SUMMARY` if set (appended), otherwise `--summary-file <path>`, otherwise `./dep-up-surgeon-summary.<ext>`. |\n| `--summary-file <path>` | Override the destination for `--summary`. Wins over `$GITHUB_STEP_SUMMARY`. |\n| `--ci` | Convenience flag for CI / bot use. Disables `--interactive`, auto-enables `--summary md` (great with `$GITHUB_STEP_SUMMARY`), and **exits `0` even when individual upgrades fail** (only pre-flight failures and fatal errors exit `1`) so per-package conflicts surface in the PR description instead of failing the job. |\n| `--git-commit` | Commit successful upgrades to git as the run progresses. Refuses to start on a dirty working tree (override with `--git-allow-dirty`). Only stages `package.json` + the lockfile (+ `pnpm-workspace.yaml` when a `catalog:` entry moved) — never `git add -A`, so unrelated WIP, generated files, and prepare/postinstall side effects are never accidentally swept into a commit. Skipped silently in `--dry-run`. |\n| `--git-commit-mode <mode>` | How to group commits: **`per-success`** (default, one commit per upgrade — best for review and `git revert`-friendly), **`per-target`** (one commit per workspace target with all its successes squashed), or **`all`** (one commit at the end with everything). Linked-group upgrades (e.g. `react` + `react-dom`) always land in a single commit regardless of mode. |\n| `--git-commit-prefix <prefix>` | String prepended to every commit message (default `\"deps: \"`). Use `\"chore(deps): \"` for [Conventional Commits](https://www.conventionalcommits.org/) or set it to your team's preferred convention. |\n| `--git-branch <name>` | Create + checkout this branch before any commits. If the branch already exists, switches to it. Pairs nicely with `--ci` for PR-bot workflows (e.g. `--git-branch \"deps/auto-$(date +%Y-%m-%d)\"`). |\n| `--git-sign` | Pass `--gpg-sign` to every commit. Requires a signing key configured in git (`user.signingkey` + `gpg.format`). Failed signatures are recorded as failed commits in the JSON report rather than aborting the run. |\n| `--git-allow-dirty` | Allow `--git-commit` to run on a dirty working tree. We still only `git add` files we touched, so your WIP isn't swept up — but if you also `git add` your own files manually, they'll land in dep-up-surgeon's commits. |\n| `--changelog` / `--no-changelog` | Fetch the bumped package's release notes (GitHub Releases first, then its published `CHANGELOG.md`) and include them in commit bodies + `--summary`. **Default ON** when `--git-commit` or `--summary` is active. Network failures are non-fatal — missing changelogs are silently skipped. See **Changelog excerpts** below. |\n| `--security-only` | Run `npm audit` (or `pnpm`/`yarn` equivalent) first, then upgrade **only** the packages with open advisories. Every successful bump carries the advisory severity + ID into its commit subject (`[security:high]`) and into the summary's **Security fixes** table. Pairs well with `--git-commit-mode per-success` to produce one PR per CVE. See **Security-first mode** below. |\n| `--min-severity <level>` | Minimum advisory severity to consider under `--security-only`: `low` (default), `moderate`, `high`, or `critical`. Lower-severity advisories are filtered out before the upgrade plan is built. |\n| `--blast-radius` / `--no-blast-radius` | Scan project source files to list which files actually `import`/`require` each upgraded package, and surface the list in `--json` + `--summary`. **Default ON** when `--summary` is active. See **Blast radius** below. |\n| `--resolve-peers` / `--no-resolve-peers` | When a linked-group bump (e.g. `react` + `react-dom` + `@types/react`) **or a single-package bump** fails with a peer-dependency conflict, compute the intersection of peer ranges across the registry packument and retry with a satisfiable version tuple (members may land below `latest`). Linked graphs with 10+ members automatically use a SAT-style AC-3 solver; single-package failures synthesize an **ad-hoc group** from direct-dep blockers named in the install output. **Default ON**. See **Peer-range intersection resolver** below. |\n| `--apply-overrides` | After the main upgrade loop, fix **transitive** CVEs that no direct bump could reach by writing a package-manager override (`overrides` for npm, `pnpm.overrides` for pnpm, `resolutions` for yarn) pinning each vulnerable transitive to its audit-recommended safe version. Runs install + validator after each pin and rolls back automatically when the validator fails. Requires `--security-only`. See **Transitive overrides** below. |\n| `--override <spec...>` | Apply one or more **manual** override pins independent of the audit. Repeatable and also accepts comma-separated values. Syntax: `<chain>@<range>`, where `<chain>` is a bare name (`lodash`), a pnpm-style chain (`some-dep>foo`, any depth), or a yarn-style chain (`parent/child`). Scoped names (`@scope/pkg`) are preserved as single chain segments. Written to the manager-native nested form (npm object, pnpm `>`-keys, yarn `/`-keys) and run through the same install + validator + rollback loop as `--apply-overrides`. Works standalone — `--security-only` is not required. See **Transitive overrides** below. |\n| `--override-force` | Used with `--apply-overrides`. Overwrite an **existing** override entry whose value conflicts with the audit-recommended version. By default we refuse to clobber user-managed pins and record `conflict` in the report. |\n| `--fix-lockfile` | After the main upgrade loop, run the package manager's native dedupe command (`npm dedupe` / `pnpm dedupe` / `yarn dedupe`) to collapse redundant transitive copies **without touching `package.json`**, and flag transitives more than a minor or a full major behind registry `latest`. Lockfile is backed up before dedupe and restored if dedupe OR the post-dedupe validator fails. Yarn classic (v1) has no dedupe subcommand — recorded as `skipped: \"unsupported\"`. See **Lockfile fix** below. |\n| `--open-pr` | After `--git-commit --git-branch` pushes the branch, open a GitHub PR with the `--summary` markdown as the body (falls back to a deterministic minimal body). Uses the `gh` CLI (must be installed + authenticated); never fatal — a missing binary, auth failure, or push rejection is recorded as `pullRequest.error` in the JSON report without aborting the run. See **Auto-opening a PR** below. |\n| `--open-pr-title <title>` | Override the PR title. Default: derived from the upgrade counts, e.g. `deps: [breaking+security] bump 3 packages`. |\n| `--open-pr-draft` | Open the PR as a draft. Recommended with `--force` or on Fridays so merge-queue bots don't auto-land it. |\n| `--open-pr-base <branch>` | Target base branch. Default: the repo default branch as reported by `gh repo view`. |\n| `--open-pr-reviewers <users>` / `--open-pr-assignees <users>` | Comma-separated usernames passed straight to `gh pr create --reviewer` / `--assignee`. |\n\nExit code `1` when any upgrade could not be kept (unless `--force`). The CLI also exits `1` when the **pre-flight** validator (run on the unchanged tree) fails — see **Pre-flight check** below. Fatal errors also exit `1`.\n\n### Pre-flight check\n\nBefore mutating any dependency, the CLI runs the resolved validator command **once** against the unchanged tree:\n\n- If it **passes**, the run continues normally.\n- If it **fails**, the run aborts immediately with an error containing the validator command, exit code, and last ~40 lines of output. This prevents the common failure mode where every per-group rollback looks identical because the project build was already broken before the run.\n- To proceed anyway, use `--validate \"<cmd>\"` to swap the validator, `--no-validate` to skip it, or `--force` to ignore the pre-flight failure.\n\n**Extra check scripts.** A build alone can pass while an upgrade breaks linting — TypeScript 7, for example, drops the JS API that `typescript-eslint` loads, so `next build` succeeds and `npm run lint` crashes. With the default validator, pre-flight therefore also runs each `lint`, `typecheck` and `type-check` script the project defines:\n\n- scripts that **pass** on the unchanged tree run after `test` / `build` on every upgrade (`Pre-flight ok: \\`npm run build && npm run lint\\``), and a failure there rolls the upgrade back;\n- scripts that **already fail** don't block the run (a warning says so) but still run after every upgrade, compared by **exit code**: the upgrade is rolled back only when the script exits differently than on the unchanged tree. Existing lint errors (ESLint exit 1) are tolerated; a crash the upgrade causes (ESLint exit 2) is not; an upgrade that fixes the script (exit 0) is fine.\n\nAn explicit `--validate \"<cmd>\"` / rc `validate` or `--no-validate` is used exactly as given. The CRA-style watch-mode trap is handled too: the `test` script runs with `CI=true` (unless you already set `CI`), so `react-scripts test` runs once instead of waiting forever.\n\nThe pre-flight outcome is also surfaced under `preflight` / `preflightAborted` in `--json` output (`preflight.extraScripts` lists the extra checks, `preflight.failingScripts` the ones that already failed, with their exit code). A run that aborts at pre-flight changed nothing, so it does not overwrite the last-run report.\n\n### Persisted last-run report\n\nAfter every CLI run that changes the project the structured report is written to `node_modules/.cache/dep-up-surgeon/last-run.json` under the workspace root (set `--no-persist-report` to opt out). Like the Nx / Babel / Vite caches it lives in `node_modules/.cache`, and the directory carries its own `.gitignore`, so **a run leaves only `package.json` and the lockfile changed in `git status`**. Deleting `node_modules` (e.g. `npm ci`) deletes the record too — run `undo` before that. Reports older versions wrote to the project root (`.dep-up-surgeon.last-run.json`) are still read; you can delete those files. `--dry-run` never writes it, so a dry run can't overwrite the record `undo` and `--retry-failed` rely on. The file mirrors the `--json` output and adds a small header (`finishedAt`, `toolVersion`, `cwd`, `dryRun`) so CI dashboards / bots can pick it up without re-running the tool. Each `upgraded` / `failed` row carries a `workspace` field when more than one target was traversed — `--retry-failed` uses that label so a freeze in one member does not skip the same package name in another. When the run changed a lockfile, its pre-run bytes are saved alongside as `last-run.<lockfile>` (e.g. `last-run.bun.lock`) for `undo`.\n\n### Retry-failed mode (`--retry-failed`)\n\nPass `--retry-failed` to **resume** the previous run instead of starting from scratch:\n\n- `dep-up-surgeon` reads the last-run report and **freezes** every package that either:\n  - **succeeded** in the last run (no need to redo work), **or**\n  - failed for a **terminal** reason: `peer` (real peer-dep conflict; bumping the same package alone almost always fails the same way) or `validation-script` (the project's own test/build script crashed; re-running won't help without a code change).\n- Freezes are **per workspace**, keyed as `workspace::name` (for example `@org/web::lodash`). A success or terminal failure in `@org/web` does **not** skip the same package in `@org/api`. Bare `--ignore` / `.dep-up-surgeonrc` ignore entries remain global (the name is skipped in every workspace). Rows from root-only runs or older reports without a `workspace` field still freeze the bare name everywhere (same as before).\n- It then **re-attempts** only the residue: failures classified as `install`, `validation-conflicts`, `versions`, or `unknown`. These are the cases where another dependency move during the new run can plausibly unblock them.\n- Linked-group failures (`name === '[group:<id>]'`) are expanded to **every member of the group** via the persisted `groups` field, scoped to the workspace that owned the group, so freezing a peer-failed group correctly freezes every package in it without leaking to other members.\n- If the last-run report is missing the CLI exits `1` with a friendly message; pass `--retry-failed` only after at least one prior run.\n\nTypical workflow:\n\n```bash\ndep-up-surgeon --workspaces           # first pass: lots of moves, some failures\n# fix the script that caused a `validation-script` failure (or accept it)\ndep-up-surgeon --retry-failed         # second pass: only retries install/conflict residue\n```\n\nMonorepo example — last run with `--workspaces`:\n\n| Package | Workspace | Last-run result | `--retry-failed` |\n|---------|-----------|-----------------|------------------|\n| `lodash` | `@org/web` | succeeded | frozen (skipped) |\n| `lodash` | `@org/api` | `install` failure | retried |\n| `react` | `@org/web` | `peer` failure | frozen (skipped) |\n| `react` | `@org/api` | not in last run | planned normally |\n\n`--ignore lodash` would still skip `lodash` in **both** workspaces. `--retry-failed` after the table above only skips the `@org/web` rows.\n\n### Summary writer (`--summary <md|html>`)\n\nPass `--summary md` (or `--summary html`) to render a human-friendly report alongside the normal output:\n\n- **GitHub Actions**: when `GITHUB_STEP_SUMMARY` is set, the Markdown summary is **appended** to that file — it shows up in the job summary tab without any extra workflow plumbing.\n- **Explicit destination**: `--summary-file <path>` overrides everything (wins over `$GITHUB_STEP_SUMMARY`).\n- **Default**: `./dep-up-surgeon-summary.<md|html>`.\n\nThe summary contains: counts (upgraded / failed / skipped), detected project info, target list, an **Upgraded** table (`Package | Workspace | From | To | Notes`), a **Failed** table (`Package | Workspace | Reason | Attempted | Detail`), pre-flight status when it aborted, and the ignored list. HTML output escapes all dynamic content. Designed to be ~40 lines of code on the producer side and easy to embed in PR comments / dashboards.\n\nThe **HTML output** is self-contained and styled: an inline `<style>` block scoped to `.dep-up-surgeon-report` gives severity chips (critical / high / moderate / low), breaking / peer-resolved / fallback / forced badges on the **Upgraded** table, clickable advisory IDs linking to `github.com/advisories/...`, and responsive tables. No external CSS or web-font requests — the file opens cleanly in any browser, and when the style tag is stripped (GitHub step-summary sanitizer) the tables still render as plain HTML. Release notes and **Blast radius** per-package blocks are folded inside `<details>` elements so the summary stays scannable.\n\n### CI / bot mode (`--ci`)\n\n`--ci` is a convenience flag for unattended runs (GitHub Actions, GitLab CI, Renovate-style bots). It:\n\n- **Disables `--interactive`** unconditionally — never blocks on stdin.\n- **Auto-enables `--summary md`** so a Markdown report lands in `$GITHUB_STEP_SUMMARY` (or `./dep-up-surgeon-summary.md` outside Actions). Pass an explicit `--summary html` if you'd rather have HTML.\n- **Remaps the exit code**: per-package failures (peer conflicts, install crashes, validation script errors) are recorded in the report and the run still exits `0`, so the bot's PR carries the diagnostic instead of the job failing red. **Pre-flight failures and fatal errors still exit `1`** — those mean the project itself is broken before any upgrade and a human needs to look.\n\nTypical GitHub Actions step:\n\n```yaml\n- name: dep-up-surgeon\n  run: npx dep-up-surgeon --workspaces --ci\n```\n\nThe job stays green; the **Summary** tab shows the upgraded / failed tables; `node_modules/.cache/dep-up-surgeon/` is cached or uploaded as an artifact (restore it into the next job's `node_modules/.cache`) so a follow-up `--retry-failed` job can resume the residue.\n\n### Git integration (`--git-commit`)\n\nPair `dep-up-surgeon` with git so every successful upgrade lands as its own atomic commit — perfect for code-review-friendly auto-update PRs.\n\n```bash\n# One commit per upgrade (best for review).\nnpx dep-up-surgeon --workspaces --git-commit\n\n# One commit per workspace target (squashed) on a fresh branch.\nnpx dep-up-surgeon --workspaces \\\n  --git-commit --git-commit-mode per-target \\\n  --git-branch \"deps/auto-$(date +%Y-%m-%d)\"\n\n# CI bot: per-success commits, Conventional Commits prefix, signed.\nnpx dep-up-surgeon --workspaces --ci \\\n  --git-commit \\\n  --git-commit-prefix \"chore(deps): \" \\\n  --git-sign\n```\n\n**Three commit modes:**\n\n- **`per-success` (default)** — one commit per upgrade. Each commit contains exactly the `package.json` + lockfile diff for one dependency. Trivial to revert any single bump (`git revert <sha>`) and trivially reviewable in a PR. Linked-group upgrades (e.g. `react` + `react-dom`) still land as one commit since they were a single install.\n- **`per-target`** — one commit per workspace target, listing every successful upgrade in the commit body. Useful for monorepos where you want each member's bumps grouped.\n- **`all`** — one commit at the end with everything. Good for tiny single-package projects; avoid in monorepos.\n\n**Safety:**\n\n- Refuses to start on a **dirty working tree** unless you pass `--git-allow-dirty`. We don't want to accidentally commit your WIP.\n- Only stages `package.json` + the lockfile — **never `git add -A`**. Files modified by `prepare`/`postinstall` hooks (e.g. `.husky/`) or other side effects of `npm install` stay uncommitted.\n- Errors out cleanly when not in a git repo (instead of silently skipping).\n- Skipped silently in `--dry-run` (no upgrades happen → nothing to commit).\n- A failed `git commit` (signing rejected, pre-commit hook refused, etc.) is recorded as `commits[].ok === false` in the JSON report with the git stderr — the upgrade itself is **never rolled back** because of a commit failure.\n\n**Concurrency-safe.** `--git-commit` works fine with `--workspaces --concurrency 8`: the same async mutex that serializes installs also serializes git invocations, so two targets can't race the index.\n\n**Structured report.** Every commit attempt (success or failure) appears under `commits` in `--json` output:\n\n```json\n{\n  \"gitCommitMode\": \"per-success\",\n  \"commits\": [\n    {\n      \"ok\": true,\n      \"sha\": \"a1b2c3d\",\n      \"message\": \"deps: bump axios from ^1.6.0 to ^1.7.2\",\n      \"files\": [\"package.json\", \"package-lock.json\"],\n      \"workspace\": \"root\"\n    }\n  ]\n}\n```\n\n### Changelog excerpts\n\nEvery successful upgrade can be annotated with the package's release notes so reviewers don't have to open five GitHub tabs per PR. Enabled by default when `--git-commit` or `--summary` is set; disable with `--no-changelog`.\n\n- **Source.** First preference is the **GitHub Releases API** (`GET /repos/:owner/:repo/releases/tags/:tag`), resolved from the package's `repository` field in its `package.json`. Fallback is the `CHANGELOG.md` extracted from the published tarball via `pacote.extract` — the matching version section is parsed out with a Markdown-aware heading scanner (handles `## 1.2.3`, `## [1.2.3] - 2024-...`, `## v1.2.3`, etc.).\n- **Where it shows up.** In `--git-commit-mode per-success`, the excerpt is embedded directly in the commit body. In `per-target` / `all` modes it collapses to a compact `See: <release-url>` footer so the commit doesn't balloon. `--summary md` / `--summary html` renders each excerpt in a collapsible `<details>` block — clean in PR bodies, compact in GitHub's Job Summary.\n- **Caching & resilience.** A run-local cache deduplicates fetches across workspaces. Network errors, missing tags, private repos, and malformed `CHANGELOG.md` files are all silently skipped — a missing excerpt never fails a commit.\n- **GitHub auth.** Anonymous GitHub API requests are rate-limited to 60/hour. Set `GITHUB_TOKEN` (or `GH_TOKEN`) in the environment to lift that to 5,000/hour — `dep-up-surgeon` uses it automatically for changelog fetches and nothing else.\n\n### Security-first mode\n\n`--security-only` flips the tool from \"bump everything safely\" to \"bump only packages with known CVEs\". Competes directly with Dependabot's security-alert surface, but runs locally and respects your validator / policy / link groups.\n\n1. Runs `npm audit --json` (or `pnpm audit --json` / `yarn audit` depending on the detected manager) **before** the upgrade plan is built.\n2. Filters the audit to advisories at or above `--min-severity <low|moderate|high|critical>`.\n3. Builds a `restrictToNames` set from the vulnerable package names and passes it to the engine — every other dependency gets added to the ignore list automatically (visible as `reason: \"ignored\"` in the report).\n4. Attaches the severity + advisory ID + title to every upgraded record's `security` field, which the CLI then propagates into:\n   - **Commit subjects**: `deps: [security:high] bump axios from 1.6.0 to 1.7.2`\n   - **Commit bodies**: full advisory ID, URL, and title\n   - **`--summary`**: a prominent **Security fixes** table above the normal upgraded table\n   - **`--json`**: `upgraded[].security = { severity, ids, url, title, vulnerableRange, recommendedVersion }`\n\n```bash\n# Only critical + high; one commit per CVE on a dedicated branch.\nnpx dep-up-surgeon --workspaces --security-only --min-severity high \\\n  --git-commit --git-commit-mode per-success \\\n  --git-branch \"deps/security-$(date +%Y-%m-%d)\"\n```\n\nThe whole path is covered by `test/unit/security-only.test.mjs` — a hermetic regression harness that drives `runAudit` with a canned `npm audit --json` blob, asserts `--min-severity` filters at every tier, and exercises the full `runUpgradeFlow` → install → validator → **rollback** cycle without touching the registry (via the `UpgradeFlowOptions.installer` injection point).\n\n### Policy engine (policy-as-code)\n\nDrop a `.dep-up-surgeon.policy.yaml` (or `.json`) in the repo root to encode upgrade rules that survive across runs and humans. Loaded automatically on startup; violations are reported per-package and the engine skips the offending bumps instead of failing.\n\n```yaml\n# .dep-up-surgeon.policy.yaml\nfreeze:\n  - pattern: react               # never touch it\n    reason: \"React 18 pinned until Q3 refactor\"\n  - pattern: \"@types/*\"          # wildcard — freezes every @types/* scope\nmaxVersion:\n  - pattern: next\n    range: \"<=14\"                # refuse anything outside this semver range\nallowMajorAfter:\n  - pattern: eslint\n    date: \"2026-06-01\"           # patch/minor OK now, majors blocked until the date\nrequireReviewers:                # metadata: surfaced in --summary / --json for your bot to consume\n  major: 2\n  minor: 1\n  patch: 0\nautoMerge:                       # metadata: ditto\n  patch: true\n  minor: false\n  include:\n    - \"eslint-plugin-*\"\n```\n\n**How rules interact**\n\n- **`freeze`** always wins. Exact names go straight into the ignore list; wildcards are matched against the scanned deps inside the engine so rules like `@types/*` don't have to be unrolled by hand. Freezes produce a `reason: \"policy\"` skip record with the originating pattern.\n- **`maxVersion`** caps the candidate list. If no candidate satisfies the range, the package is skipped with `reason: \"policy\"` — it won't degrade to a no-op install.\n- **`allowMajorAfter`** blocks **cross-major** bumps until the specified date (checked against `Date.now()`), demoting the candidate to the newest in-major version. Patch/minor still flow through normally.\n- **`requireReviewers`** and **`autoMerge`** are **metadata only** — attached to the `policy` block of `--json` + `--summary` for downstream automation (GitHub Actions PR-opener, the SaaS bot, etc.) to consume.\n\nEvery applied rule appears in the **Policy** section of `--summary` and under `policy.applied` / `policy.frozen` / `policy.warnings` in `--json`, so audits show exactly which rule blocked which package.\n\n### Blast radius\n\nBefore handing the PR to a reviewer, `dep-up-surgeon` can list **which of your own source files actually import each upgraded package**. Surfaced automatically under `--summary`; attach it to `--json` too with `--blast-radius`.\n\n- **Scans**: `.ts`, `.tsx`, `.js`, `.jsx`, `.mjs`, `.cjs`, `.mts`, `.cts`, `.vue`, `.svelte`, `.astro`.\n- **Skips**: `node_modules`, `dist`, `build`, `coverage`, `.git`, `.next`, `.turbo`, `.vercel`, `.cache`, `.parcel-cache`, `out`, `.output`.\n- **Detects**: ES imports (`import x from '<pkg>'`), re-exports (`export … from '<pkg>'`), CommonJS `require('<pkg>')`, dynamic `import('<pkg>')`, and subpath imports (`from '<pkg>/sub'` still counts as a hit on `<pkg>`). Word-boundary safe — looking for `react` does not falsely match `react-dom`; looking for `@types/node` does not match `@types/node-ipc`.\n- **Output**: per-package `{ total, truncated, files[] }` entries in `upgraded[].blastRadius`, plus a collapsible per-package list in the Markdown / HTML summary. Caps at 20 file paths per package by default; `total` keeps counting past the cap so the summary can honestly say \"used in 134 files\".\n- **Cost**: a single pass over the tree, at most 1 MB read per file, parallel I/O (default concurrency 8). Failures are non-fatal — a broken symlink never aborts the run. Turn it off in huge monorepos with `--no-blast-radius`.\n\n### Breaking-change detection\n\nWhenever a changelog excerpt is fetched, `dep-up-surgeon` scans it for breaking-change markers and flags the upgrade so reviewers catch them before clicking merge. Works alongside `--changelog` (enabled by default with `--git-commit` / `--summary`) with no extra flags.\n\n- **What we match**: `BREAKING CHANGE:` / `BREAKING CHANGES:` footers (Conventional Commits), the `💥` and `⚠️  BREAKING` emoji conventions used by Changesets / tsup / Vitest, explicit Node-version drops (`drop support for Node 16`, `requires Node >= 20`), API-removal bullets (`- Removed the …`), and `no longer supported` / `renamed … to …` phrasing. Deprecation notices alone do **not** trip the scan.\n- **Where it shows up**:\n  - **Commit subjects** gain a `[breaking]` tag (emitted BEFORE `[security:<sev>]` when both apply): `deps: [breaking][security:high] bump axios from 1.6.0 to 2.0.0`.\n  - **Commit bodies** get a `Breaking changes detected:` section listing the exact matched lines, capped at 5 per package.\n  - **`--summary md|html`** renders a prominent `⚠️ Breaking changes detected` section ABOVE the upgraded table, plus a `⚠️ breaking` badge in the Notes column.\n  - **`--json`** → `upgraded[].changelog.breaking = { hasBreaking, matchedLines[], reasons[] }` (only present when the scan matched).\n- **Never fatal, never noisy**: absence of a changelog means no scan, which means no flag. The scan caps matches at 10 per package and dedupes identical lines so verbose changelogs don't drown out the signal.\n\n### Peer-range intersection resolver\n\nLinked-group bumps (e.g. `react` + `react-dom` + `@types/react`, or the Jest / Testing-Library / Vitest families) frequently fail because one member's **latest** demands a peer version another member can't yet satisfy. Without help, the whole batch rolls back and the user has to figure out the right tuple by hand.\n\n`--resolve-peers` (default ON) turns this into an automated constraint-satisfaction problem:\n\n1. The first batch attempt runs exactly like today — every linked member goes to its registry `latest`.\n2. If the install fails with a **peer** conflict, the resolver fetches each linked package's full registry packument (cached — one call per package per run) and reads every published version's `peerDependencies` block.\n3. Each member gets a candidate domain: every version between `currentRange`'s `minVersion` and the originally-requested target, sorted newest-first, minus deprecated / pre-release versions.\n4. A **newest-first backtracking search** enumerates version tuples (variable = one package, domain = its candidate versions). For each partial assignment, every peer constraint that has become knowable is checked; peers on packages inside the linked group are checked against the chosen version, peers on packages OUTSIDE the group are checked against that package's range in the current `package.json` (via `semver.minVersion`).\n5. For **large linked graphs (≥ 10 members)** — where the 400-tuple backtracking budget can be burned before the solver escapes the first variable's domain — the resolver automatically switches to a **SAT-style path** (arc-consistency + least-constraining-value DFS). It pre-prunes every member-version that can't be satisfied against external peers, runs up to 128 AC-3 rounds across every ordered member pair until the pruned domains reach a fixed point, then does an **MRV-ordered** (smallest domain first) newest-first DFS on whatever survived. For monorepo link groups up to ~50 members × ~30 recent versions this finishes in milliseconds where plain DFS would return `undefined`. When the SAT path fails the dispatcher falls back to the plain backtracker automatically.\n6. The **first** complete tuple to satisfy every constraint is also the least-downgrade one. The engine rewrites the batch's target versions and retries the install + validator. On success, every affected row is tagged with `resolvedPeer = { originalTarget, reason, tuplesExplored }` — `reason` carries a `[backtracking]` or `[sat]` method tag so reviewers can tell which solver path produced the tuple.\n7. If the resolver can't find a satisfiable tuple, or the retried install still fails, the batch falls back to the pre-resolver behavior (rollback + `kind: 'peer'` failure row).\n\n**Ad-hoc resolver for non-linked bumps.** Single-package upgrades that fail with a peer conflict used to be rolled back unconditionally — the resolver was linked-groups-only. Now we synthesize an **ad-hoc group** from the parsed install output: the primary + every blocker named in the peer-conflict lines that's **already a direct dep** of the workspace (peers on unknown transitives stay out of scope). The same resolver (and the same SAT fallback) runs on that synthesized group. On success the engine writes a small batch: the primary at whatever version the resolver picked, plus any blocker the resolver wants moved within its **current pinned range** (the ad-hoc path is allowed to downgrade the primary, never to silently bump a blocker past its pin).\n\nGuard rails that keep it safe:\n\n- **Bounded search** — capped at 400 tuples explored per batch (small graphs) or `400 × members` tuples for the SAT path's DFS phase. Past that the resolver gives up silently instead of hanging the run on pathological inputs.\n- **Optional peers** (`peerDependenciesMeta[name].optional === true`) are ignored. An unsatisfied optional peer isn't a hard conflict.\n- **Installed direct deps outside the batch still bound it** — each member's candidates are narrowed to versions that satisfy the peer ranges declared by the installed direct dependencies that aren't being bumped (a package already at latest never joins the batch, but its peers still count).\n- **Deprecated versions** never appear in the domain. We'd rather fail to find a solution than auto-suggest a known-bad version.\n- **Ad-hoc group size cap** — default 6 members (primary + up to 5 direct-dep blockers). Prevents registry fetch storms on pathological peer graphs.\n- **Ad-hoc never adds dependencies** — a peer on a transitive that isn't already a direct dep is ignored rather than introduced.\n- **`--force` bypasses the resolver** — the user has explicitly opted into barreling through peer conflicts.\n- **`--no-resolve-peers`** keeps the old behavior when you WANT peer failures to surface so a human resolves them instead of the tool silently nudging versions off latest. Applies to both the linked-group and ad-hoc paths.\n\nWhere it shows up:\n\n- **Console output**: `upgraded: react-dom → 18.3.1 (group react-pair) [peer-resolved from 19.0.0]`.\n- **`--summary md|html`**: a dedicated **Peer-range resolutions** table (package / group / requested / installed / tuples explored) above the upgraded table, plus a `peer-resolved from <v>` badge in the upgraded row's Notes column.\n- **Commit subjects**: `[peer-resolved]` tag sits between `[breaking]` and `[security:<sev>]` (stable order). The body gets a `Peer-range resolutions (kept linked group satisfiable):` footer listing each pinned member.\n- **`--json`**: `upgraded[].resolvedPeer = { originalTarget, reason, tuplesExplored }` plus `upgraded[].requestedLatest` still reflects the pre-resolver target so downstream tools can diff them.\n- **Kept at the installed version**: when the resolver's tuple is what's already installed, the group isn't installed and validated again. The members are reported as skipped `no change` rows with `requestedLatest` and `blockedBy: [{ name, version, range }]`, e.g. `@react-three/fiber` `9.7.0` needing `react` `>=19 <19.3`.\n\n### Transitive overrides (`--apply-overrides` / `--override`)\n\n`--security-only` by itself can only fix vulnerabilities reachable from a direct dependency. For CVEs that live in transitives (very common — `lodash@4.17.20` buried six levels deep under a toolchain package), pair `--security-only` with `--apply-overrides` and the tool will write a package-manager override to pin the vulnerable transitive to its safe version.\n\n- **Which field**: `overrides` for npm (>=8.3), `pnpm.overrides` for pnpm, `resolutions` for yarn (classic + berry).\n- **How it picks the pin**: uses the audit's own `fixAvailable.version` when present; otherwise `minVersion` of the first safe range the manager reported.\n- **Rollback on failure**: after each override, the tool runs a full install and then the validator. If either fails, the override is removed, install re-runs to restore the starting state, and the next advisory is still attempted. A failed override never strands the workspace — `report.overrides.attempts[].rolledBack === true` appears in the JSON and the summary.\n- **Conflict protection**: when the user already has a manual override with a value that **conflicts** with the audit recommendation, we refuse to clobber by default (`reason: \"conflicts with target ...\"`). Pass `--override-force` to overwrite explicitly.\n- **Where it shows up**:\n  - **`--summary`**: dedicated `Overrides applied` table with `Package / Pinned to / Source / Severity / Advisory`. Parent-scoped pins render as `a › b › c` so the chain is visible at a glance.\n  - **`--json`**: `overrides.field` + `overrides.attempts[]` with the full decision trail (`ok`, `skipped`, `reason`, `previous`, `applied`, `installLog`, `rolledBack`, `chain`, `source`). Parent-scoped pins carry `chain: [\"parent\", \"child\"]`; `source` distinguishes `\"advisory\"` from `\"manual\"`.\n\n#### Parent-scoped pins (`--override`)\n\n`--apply-overrides` only writes the **flat** `name → version` form — every occurrence of the package gets pinned. When you need to pin a transitive **only when it appears under a specific parent** (e.g. you want `foo@1.2.3` under `some-dep` while the rest of the tree uses `foo@2.x`), use `--override` to write a **parent-scoped** selector. Works standalone — no `--security-only` required.\n\nSyntax: `<chain>@<range>`. The chain supports three forms, all normalized internally:\n\n- **Flat**: `--override lodash@4.17.21` → same shape as a classic flat override.\n- **pnpm-style**: `--override \"some-dep>foo@1.2.3\"` — pin `foo` only when nested under `some-dep`. Chains of any depth (`a>b>c>d@1.0.0`) are supported.\n- **yarn-style**: `--override \"parent/child@1.2.3\"` — `/` separator; `@scope/pkg` stays intact as a single chain segment.\n\nEach selector is written to the **manager's native nested encoding**:\n\n| Manager | Shape written |\n| --- | --- |\n| npm | `{ \"overrides\": { \"some-dep\": { \"foo\": \"1.2.3\" } } }` — nested object; an existing flat pin for the parent is preserved via npm's `\".\"` self-selector. |\n| pnpm | `{ \"pnpm\": { \"overrides\": { \"some-dep>foo\": \"1.2.3\" } } }` — pnpm's `>`-chain keys, deep chains supported. |\n| yarn | `{ \"resolutions\": { \"some-dep/foo\": \"1.2.3\" } }` — `/`-chain keys. |\n\nEvery pin runs through the same install + validator + rollback loop as advisory-driven pins. A failed manual pin is rolled back (only that specific slot) and the rest of the run continues; a flat pin and a parent-scoped pin with the same leaf name coexist as separate entries.\n\n```bash\n# Pin `lodash@4.17.21` ONLY when it's a transitive of `some-dep`, and pin `axios@1.6.0`\n# globally. Both live in the same run; one failing never touches the other.\nnpx dep-up-surgeon \\\n  --override \"some-dep>lodash@4.17.21\" \\\n  --override \"axios@1.6.0\" \\\n  --validate \"npm test\"\n```\n\n```bash\n# Weekly security sweep: direct bumps first, then transitive overrides (audit-driven +\n# one manual pin), then a draft PR.\nnpx dep-up-surgeon --workspaces \\\n  --security-only --min-severity high \\\n  --apply-overrides \\\n  --override \"@babel/core>@babel/traverse@7.23.2\" \\\n  --git-commit --git-commit-mode per-success --git-branch \"deps/security-$(date +%Y-%m-%d)\" \\\n  --summary md \\\n  --open-pr --open-pr-draft\n```\n\n#### Override policy file (`.dep-up-surgeonrc` `overrides`)\n\nRe-typing `--override \"parent>child@1.2.3\"` on every CI run gets old fast. Commit the pins to `.dep-up-surgeonrc` instead and they'll apply on every run the same way `ignore` does — merging with any CLI `--override` flags on the same invocation (**CLI wins on chain conflict**). The committed form supports a `reason` string that flows straight into the report + summary so reviewers can see **why** each transitive is pinned (CVE ID, vendor guidance, upstream PR link) without grepping commit history.\n\nTwo input shapes are accepted:\n\n```jsonc\n{\n  \"overrides\": [\n    // Structured: explicit chain + range. `chain: \"lodash\"` is shorthand for the flat case.\n    { \"chain\": [\"some-dep\", \"foo\"], \"range\": \"1.2.3\", \"reason\": \"CVE-2025-1234\" },\n\n    // Selector form: same syntax as the `--override` CLI flag.\n    { \"selector\": \"@babel/core>@babel/traverse@7.23.2\", \"reason\": \"upstream PR #16012 pending\" },\n    { \"selector\": \"lodash@4.17.21\" }\n  ]\n}\n```\n\nBehavior:\n\n- **Merge + dedupe**: entries are merged with CLI `--override` selectors by exact chain. A CLI pin for the same chain **replaces** the rc entry (including the `reason`), so one-off ad-hoc overrides always win over committed policy.\n- **Malformed CLI selectors are warnings**, not fatal: a typo in one `--override` flag won't prevent committed rc pins from applying. rc entries with a bad shape produce per-entry warnings in `.dep-up-surgeonrc.warnings` and the run continues.\n- **Same lifecycle as `--override`**: every pin goes through the install + validator + rollback loop. Failures are per-pin — one bad pin never strands the rest.\n- **`reason` surfaces in the report**: the `Overrides applied` table in `--summary` adds a `Reason` column whenever at least one attempt carries one; `--json` ships `overrides.attempts[].policyReason` verbatim for bots.\n\n```bash\n# Run the committed overrides policy. No CLI flags needed; `overrides: [...]` in\n# `.dep-up-surgeonrc` is enough to trigger the flow.\nnpx dep-up-surgeon --summary md\n\n# Add a one-off pin on top of the committed set for this run only:\nnpx dep-up-surgeon --override \"lodash@4.17.21\" --summary md\n```\n\n### Disaster recovery (`dep-up-surgeon undo`)\n\nEvery run writes a last-run report (`node_modules/.cache/dep-up-surgeon/last-run.json`) — a structured record of what the tool did (previous ranges, `to` values, every override attempt with `applied`/`previous`, workspace targets). `dep-up-surgeon undo` replays that record **in reverse**:\n\n1. For every successful upgrade row, write the recorded `from` back to `package.json` (in whatever section currently holds the dep, across the root and every workspace target).\n2. For every successful override attempt, drop the pin we added — or, when the attempt recorded a `previous` value (the run replaced an existing pin), restore that previous value.\n3. Put back the pre-run bytes of every root lockfile the run changed (the run saved them next to the report as `last-run.<lockfile>`), then run `<manager> install` once per edited target. Reinstalling alone isn't enough: a reverted `^16.3.1` still allows the `16.3.5` the run installed, so without the backup those versions would stay.\n4. Run the validator so you see green/red before you commit the revert.\n\nDrift protection:\n\n- If the current `package.json` value for a dep **doesn't match** the `to` the run landed on (another run, or a human edit, moved it), the row is **skipped** with `reason: 'drifted'`. Undo never rewrites state we don't recognize.\n- The lockfile backup is only restored when **every** row reverted and the lockfile still hashes to what the run left behind; otherwise undo says why (`lockfile bun.lock: not restored (…)`) and falls back to reinstalling from the reverted ranges.\n- When the recorded run was `--dry-run`, undo is a **no-op**.\n- Missing / unparseable run report → the command exits with status 2 and a clear error message.\n\n```bash\n# Replay the newest recorded run in this directory.\nnpx dep-up-surgeon undo\n\n# Compute the reverse plan WITHOUT touching the disk. Use for review/CI dry-runs.\nnpx dep-up-surgeon undo --dry-run\n\n# Replay a specific run file (e.g. from a CI artifact).\nnpx dep-up-surgeon undo --file ./ci-logs/2026-04-18-upgrade.last-run.json\n\n# Skip the validator — handy when the project has no test script but you still want the\n# dep ranges rolled back.\nnpx dep-up-surgeon undo --no-validate\n```\n\n| Option | Description |\n|--------|-------------|\n| `--file <path>` | Replay a specific last-run report instead of `node_modules/.cache/dep-up-surgeon/last-run.json`. |\n| `--json` | Emit the structured `UndoResult` on stdout. |\n| `--dry-run` | Print the reverse plan without touching disk. |\n| `--no-validate` / `--validate <cmd>` | Skip or override the post-reverse validator. |\n| `--skip-install` | Skip the post-reverse `<manager> install` (lockfile will otherwise diverge). |\n| `--package-manager <mgr>` | Override the manager recorded in the run report. |\n| `--cwd <path>` | Run against a different directory. |\n\nExit codes: `0` = reverse pass succeeded (or was a no-op); `1` = install or validator failed during the reverse pass (the JSON report still explains which rows moved); `2` = the run report was missing / invalid. Pair with `--json` for CI pipelines — the full `UndoResult` is emitted on stdout.\n\n### Lockfile fix (`--fix-lockfile`)\n\n`--fix-lockfile` improves the **lockfile's** dependency graph without touching `package.json`. It's the counterpart to `--apply-overrides`: where overrides fix vulnerable transitives, `--fix-lockfile` collapses redundant ones and surfaces the stale-but-not-vulnerable tail that a direct upgrade loop can never reach.\n\nWhat it does:\n\n- **Dedupe**: runs the package manager's native dedupe command — `npm dedupe --no-audit` / `pnpm dedupe` / `yarn dedupe` (berry only). These commands collapse multiple copies of the same package when semver ranges allow it.\n- **Stale-transitive scan**: for the top 250 packages in the lockfile (by installed-copy count), cross-references registry `latest` and flags any package whose highest installed version is more than one minor OR a full major behind. Trivial drift (a patch or a single minor) is filtered out — only the drifted-by-6-months cases show up.\n- **Backup + rollback**: lockfile is snapshotted before dedupe. If dedupe exits non-zero OR the post-dedupe validator fails, the snapshot is restored and the manager is re-run to reconcile `node_modules`. The worst case is the same tree you started with.\n\nGuard rails:\n\n- **Yarn classic (v1)** has no `dedupe` subcommand — recorded as `skipped: \"unsupported\"` and the rest of the run continues normally.\n- **Bun** likewise has no `dedupe` subcommand — recorded as `skipped: \"unsupported\"`.\n- **No lockfile on disk** → `skipped: \"no-lockfile\"`. Nothing to dedupe when the install has never been run.\n- Runs **after** `--apply-overrides` so the final tree includes security pins before dedupe.\n\nWhere it shows up:\n\n- **Console**: one-line summary — `--fix-lockfile: npm dedupe ... succeeded (12 packages deduped/updated, 3 stale transitives flagged)`.\n- **`--summary md` / `--summary html`**: a dedicated **Lockfile fix** section with a `merged`/`updated` diff table, a collapsible **Stale transitives** details block, and the last lines of the dedupe/validator output on failure.\n- **`--json`**: `lockfileFix: { status, manager, lockfile, command, dedupeChanges[], stale[], ... }` with the full structured diff.\n\n```bash\n# Post-security-sweep cleanup: dedupe the tree and surface stale transitives in the PR body.\nnpx dep-up-surgeon --security-only --apply-overrides --fix-lockfile --summary md\n```\n\n### Doctor subcommand (`dep-up-surgeon doctor`)\n\n`doctor` is a **read-only** diagnostic that answers one question: \"is this project in good shape for an upgrade pass right now?\". Run it before trusting an upgrade loop (or as a CI pre-check); it never mutates anything. Output is a **traffic-light report** — green/yellow/red per check with a remediation hint on anything non-green.\n\nWhat it checks, in order (stable IDs for `--json` consumers):\n\n1. **`node-version`** — current Node satisfies `engines.node` (if set). Red when a mismatched Node would tear down peer-dep resolution in ways that look like CVE-driven failures later.\n2. **`manager`** — a single package manager was resolved cleanly. Yellow when multiple lockfiles coexist or the tool had to fall back to the `npm` default without any signal.\n3. **`lockfile`** — the lockfile is parseable. Yellow on npm v1 shape (upgrades to v2 recommended); red on unreadable / corrupt files.\n4. **`dependencies-installed`** — declared dependencies are actually installed (`node_modules`, or Yarn Plug'n'Play). Red when they aren't, with a `<mgr> install` hint — otherwise the validator and peer scan below fail for that reason alone and bury the real cause.\n5. **`workspace-coherence`** — declared workspace members resolve on disk with their own `package.json`.\n6. **`policy`** — `.dep-up-surgeon.policy.{yaml,json}` (when present) parses without warnings.\n7. **`preflight-validator`** — your `<mgr> test` / `<mgr> run build` (or `--validate <cmd>`) passes right now, before any upgrade. Red here means the project is broken **before** the upgrade loop — fix that first or every failure downstream will look like a regression.\n8. **`peer-deps`** — existing peer / missing dep warnings (via `npm ls --all`, `pnpm install --frozen-lockfile --offline`, or `yarn check`). Catches \"already broken before you touched it\" cases.\n9. **`audit`** — `<mgr> audit` dry-run with severity breakdown. Red on any high/critical advisory, yellow on low/moderate.\n10. **`stale-transitives`** — up to 100 transitives scanned against registry `latest`; yellow when any are more than a minor or a full major behind. Informational (never red); run `--fix-lockfile` to clean up the easy ones.\n\nExit codes:\n\n- `0` — all checks green (or yellow-only without `--strict`)\n- `1` — any yellow under `--strict`\n- `2` — any red\n\nOptions are focused (no entanglement with the 70+ upgrade-flow flags):\n\n| Option | Description |\n|--------|-------------|\n| `--json` | Emit the full `DoctorReport` as JSON on stdout instead of the human format. |\n| `--strict` | Treat yellow checks as failures (exit 1 instead of 0). Use for CI gates. |\n| `--no-validate` | Skip the pre-flight validator check. |\n| `--validate <cmd>` | Override the validator command used by the pre-flight check. |\n| `--skip-audit` | Skip the audit dry-run. Use for air-gapped CI / offline dev. |\n| `--skip-peer-scan` | Skip the peer-dep scan (slow on huge trees). |\n| `--skip-stale-scan` | Skip the registry-backed stale-transitive scan. |\n| `--package-manager <mgr>` | Override detected manager: `auto`, `npm`, `pnpm`, `yarn`, `bun`. |\n| `--cwd <path>` | Run against a different directory. |\n\n```bash\n# Quick CI pre-check\nnpx dep-up-surgeon doctor --strict --json\n\n# Local \"should I trust the upgrade loop?\" check\nnpx dep-up-surgeon doctor\n```\n\n### Outdated report (`dep-up-surgeon outdated`)\n\n`outdated` is a **read-only** scan of direct dependencies vs registry `@latest`. Installed versions come from the lockfile when available (so `^1.0.0` that already resolved to `1.9.0` is not flagged if `1.9.0` is latest). When the `latest` dist-tag lags behind the installed major, the newest release of that major is reported as `latest` (the tag itself goes to `latestTag`; see **Why not only “latest”?**). Exits `1` when anything is outdated, `2` when no package could be checked (every registry lookup failed), `0` otherwise — useful as a CI soft gate before an upgrade run.\n\n```bash\nnpx dep-up-surgeon outdated\nnpx dep-up-surgeon outdated --json\nnpx dep-up-surgeon outdated --include-peers\n```\n\n| Option | Description |\n|--------|-------------|\n| `--json` | Emit the structured `OutdatedReport` on stdout. |\n| `--include-peers` | Include `peerDependencies` (skipped by default). |\n| `--package-manager <mgr>` | Override detected manager: `auto`, `npm`, `pnpm`, `yarn`, `bun`. |\n| `--cwd <path>` | Run against a different directory. |\n\n### Auto-opening a PR (`--open-pr`)\n\nWhen you've already paid the cost of running `--git-commit --git-branch`, `--open-pr` closes the loop by pushing the branch and opening a GitHub pull request via the [GitHub CLI (`gh`)](https://cli.github.com/). Uses your existing `gh auth`; the tool handles nothing sensitive.\n\n- **Body**: the Markdown `--summary` file when one was written, otherwise a deterministic minimal body listing upgraded packages. `gh pr create --body-file -` is used so the body is piped via stdin (no argv quoting hell for multi-KB Markdown).\n- **Title**: derived from the upgrade counts — e.g. `deps: [breaking+security] bump 3 packages` — or any string you pass via `--open-pr-title`.\n- **Base branch**: resolved from `gh repo view` when not explicitly given; respects your default branch setting.\n- **Reuses existing PRs**: if a PR already exists for the same head branch, we return `{ reused: true }` instead of erroring.\n- **Never fatal**: a missing `gh` binary, an unauthenticated session, a rejected push, or a 4xx from the API is recorded as `pullRequest.error` in the JSON report and printed to stderr — the upgrade commits are still on disk, and a subsequent manual `gh pr create` or `git push` will work normally.\n- **Draft mode**: pass `--open-pr-draft` to open as a draft (recommended with `--force` or when the breaking-change badge fires).\n\n```bash\n# Full \"open a proper PR\" flow with reviewers + draft mode.\nnpx dep-up-surgeon --workspaces --summary md \\\n  --git-commit --git-commit-mode per-success --git-branch deps/weekly \\\n  --open-pr --open-pr-draft \\\n  --open-pr-reviewers alice,bob --open-pr-base main\n```\n\n### Workspaces & package managers\n\n`dep-up-surgeon` is **workspace-aware**:\n\n- **Detection.** On startup the tool resolves the **package manager** (`npm` / `pnpm` / `yarn` / `bun`) by reading, in order: the `--package-manager` flag, the `packageManager` field in `package.json`, the lockfile (`pnpm-lock.yaml` → pnpm, `yarn.lock` → yarn, `bun.lock` / `bun.lockb` → bun, `package-lock.json` → npm), the presence of `pnpm-workspace.yaml`, and finally falls back to `npm`. **Workspace globs** are read from `workspaces` (npm/yarn/bun — both array and `{ packages: [...] }` forms are supported) **or** `pnpm-workspace.yaml` (`packages:` list).\n- **Install + validator follow the manager.** `<mgr> install` runs after each bump and the default validator becomes `<mgr> test` → `<mgr> run build` (yarn classic uses `yarn build`). Override with `--validate \"<cmd>\"` if you need something different (e.g. `pnpm -r build`).\n- **Workspace-internal deps are skipped automatically.** If a dependency name matches a local workspace package, the tool does not try to resolve it from the npm registry — it appears in the report as `skipped` with `detail: \"workspace-internal dep …\"`. Pass `--include-workspace-deps` to override (useful when those packages are **also** published).\n- **Workspace child traversal (`--workspaces` / `--workspaces-only` / `--workspace <names>`).** By default only the **root** `package.json` is mutated. With `--workspaces`, the tool **also** scans every member's `package.json` (one engine pass per file), but **install + validation always run from the workspace root** so the lockfile resolves correctly and the validator sees the entire monorepo. Pre-flight runs **once** at the workspace root regardless of how many targets are traversed. Every `upgraded` / `failed` row in the report is tagged with a `workspace` field (`\"root\"` or the member's package `name`) so you can tell at a glance which `package.json` produced each change. `--retry-failed` uses that field to freeze successes and terminal failures **in that workspace only** — the same package name in another member is still a candidate.\n- **Install mode (`--install-mode root|filtered`).** Default is","readmeFilename":"README.md"}