Dependency Patch Run
The libraries your application is built on have moved on since it was written, and some of the versions it is pinned to now have published vulnerabilities. We bring them current, run your test suite, and tell you exactly what moved and why. This is the routine hygiene that stops happening the month the original developer leaves.
What you get
- Dependencies updated for one application, within the major versions it already runs
- Your test suite run before and after, with both results in writing
- A changelog of every package that moved, the version it moved to, and the reason — security advisory, bug fix, or plain currency
- The work delivered as a branch or pull request for your review, not pushed to production by us
What this does not cover
- Major-version upgrades that require changes to your own code. We will list the ones waiting and say what each would take; doing them is separate work.
- Repairing a test that was already failing before we started. We report it; fixing it is a Bug Fix Block.
- Deploying the result. Your own pipeline can, or a Managed Deployment Window will.
- Verification on an application with no test suite. Without one there is no automated way to tell a safe update from a breaking one, so tell us when you order and we will scope the checking rather than let a clean run imply something it did not test.
Who it fits
An application a year or two behind and otherwise working fine. If you also want the small fixes and someone reading the error log between runs, the Application Maintenance Retainer covers this and those together.