agent ignored the deprecation warnings in npm output and missed that the package was deprecated
Fixes upgrades that landed on a deprecated package because the agent scrolled past npm's deprecation warnings. Use when npm output shows a package is deprecated, or an upgrade PR bumped to a version the maintainers have abandoned. Key trigger: npm prints a deprecation notice for the package during install.
TL;DR
Treat deprecation warnings as blockers in the agent's upgrade loop, not noise. Run npm view [pkg] deprecated to confirm, then replace the package with a maintained alternative instead of upgrading within the dead line. Deprecation means no future security fixes, so staying on the package is a slow-growing vulnerability.
Error
agent ignored the deprecation warnings in npm output and missed that the package was deprecatedSteps
- Confirm the deprecation. Run
npm view [pkg] deprecated. Expected: it prints the deprecation message (or nothing, meaning the package is fine and the warning came from elsewhere). - Find which dependency pulls it in. Run
npm ls [pkg]to see the chain. Expected: you see whether it is direct or transitive. - Pick a maintained replacement. Search for the package's successor - the deprecation message usually names one. Expected: a candidate with recent releases and a compatible API.
- Swap it out. Run
npm uninstall [pkg], install the replacement, update the imports, and run the test suite. Expected: tests pass and the deprecation warning is gone from install output. - Teach the agent. Add a step to the upgrade loop that fails or warns loudly when
npm view [pkg] deprecatedreturns a message. Expected: future upgrade PRs never bump a deprecated package silently.
Use this when
- npm install output contains "deprecated" for a package you depend on
- An upgrade PR bumped a package whose maintainers have abandoned it
- You want the agent to stop treating deprecation warnings as ignorable noise
- A transitive dependency is deprecated and you need to find the chain
Not for this skill when
- The warning is about a deprecated npm CLI flag or Node API, not a package - different fix
- The package is deprecated but you have already decided to keep it pinned intentionally
- The deprecation is a false positive from a stale registry cache - re-check after clearing it
Variant phrasings
- npm warns package is deprecated after upgrade
- agent upgraded to a deprecated version
- how to find which package triggers a deprecation warning
- replace a deprecated npm package
Why it happens
npm prints deprecation warnings to stderr mid-install, mixed in with hundreds of other lines. Agents that parse install output for errors only look for non-zero exits, so warnings scroll past unnoticed. Nothing in the default upgrade flow asks "is this package still maintained," so deprecated packages keep getting version bumps.
Edge cases
- A package can be deprecated without a replacement named - check the repo's README and issue tracker for the maintainers' recommendation.
- Sometimes only specific version ranges are deprecated;
npm view [pkg] timeshows the release timeline so you can tell whether the whole line is dead. - If the deprecated package is transitive and the direct parent is also unmaintained, you may need to replace the parent, not just the child.
- Deprecation warnings can come from optional dependencies on platforms you do not use - verify the warning applies to your platform before ripping things out.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_jRIuG2zIb-HW0pql9EpAOw