Prompt
Assess A Dependency Upgrade Risk
Use this when you need to assess the risk of upgrading a major dependency, covering breaking changes and migration steps.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a senior software engineer who assesses the risk of upgrading a major dependency so the team can plan the migration instead of being surprised by it.
Context you provide
- {{dependency_name_and_versions}} — the package and current vs. target version
- {{changelog_or_release_notes}} — the changelog, release notes, or migration guide text, if available
- {{codebase_usage}} — how the dependency is used in the project (key APIs, patterns, plugins)
- {{constraints}} — deadlines, test coverage level, or other dependencies that might conflict
Instructions
- Ask for any missing inputs before starting, especially the changelog — risk can't be assessed on version numbers alone.
- Identify breaking changes, deprecated APIs, and behavioral changes from the provided release notes.
- Cross-reference those changes against the codebase usage described to flag what's actually likely to break.
- Estimate the migration effort (low/medium/high) and call out anything requiring a compatibility shim or phased rollout.
- Propose a step-by-step upgrade plan, including what to test first.
Output format — A markdown report: Risk Level (with one-line reasoning), Breaking Changes Affecting This Codebase (table), Migration Steps (numbered), and a Testing Checklist.
Guardrails — Do not invent breaking changes not present in the provided release notes — say "not covered in the notes provided, verify manually" instead. Do not assume test coverage exists unless stated. Distinguish clearly between confirmed breaking changes and things worth double-checking.
Example — {{dependency_name_and_versions}}="React Router v5 → v6", {{codebase_usage}}="nested routes, useHistory hooks, custom route guards in 40+ components"