Review package upgrades
Compare the versions you currently use with proposed upgrades for up to 30 packages. Each review brings together security advisories, dependency changes, compatibility information, and release notes to help you decide what to upgrade.
Reviews identify gaps in the available information so you can see where an upgrade needs further investigation.
Selector catalogue
Use the following selectors with the fields query parameter to choose which fields the response includes. See Choose what the response includes for details.
| Selector | Data | Default |
|---|---|---|
security.direct | Security advisories for the current and target versions, including advisories introduced, fixed, or unchanged by the upgrade. | Yes |
security.transitive | Security changes in indirect dependencies, with counts and affected package details. Each detail list includes up to 50 packages and indicates truncation. | Yes |
dependencies.direct | Direct dependencies added, removed, or changed, including version constraints and resolved versions. | Yes |
dependencies.transitive | Indirect dependencies added, removed, or changed. | Yes |
dependencies.issues | Counts and names of newly deprecated, duplicate, conflicting, or outdated dependencies. | No |
compatibility | Peer dependency changes and compatibility notes. | Yes |
changelog | Release-note summaries, previews, sources, and change signals for the upgrade range. Entry and keyword-match lists each contain up to 20 items, with coverage and truncation information. | Yes |
changelog.body | Full release-note text for entries and keyword matches. Also includes changelog. | Yes |
security.* | Both direct and transitive security groups. | No |
dependencies.* | All dependency change and issue groups. | No |
changelog.* | Changelog summaries and full release-note text. | No |
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
Optional client attribution: trimmed printable ASCII, at most 80 bytes. Invalid optional values are dropped.
Optional client-version attribution: trimmed printable ASCII, at most 80 bytes. Invalid optional values are dropped.
Optional agent attribution: trimmed printable ASCII, at most 160 bytes. Invalid optional values are dropped.
Optional session attribution: trimmed printable ASCII, at most 128 bytes. Invalid optional values are dropped; no session is created.
Query Parameters
Finite comma-separated atomic groups. Explicit selection replaces defaults; see catalogue.
Use the case-sensitive selectors in the catalogue. Order and duplicate selectors do not affect the result. ASCII whitespace around selectors is ignored. The decoded value is limited to 2048 UTF-8 bytes. Empty or unknown selectors and repeated fields query parameters return 400 VALIDATION_ERROR. A group does not include nested groups unless the catalogue says so; only listed wildcard bundles are supported.
Body
Ordered canonical batch; unknown/duplicate JSON keys fail validation; rows are never silently removed.
One to thirty packages; all recognized registries, no silent row removal.
1 - 30 elementsOptional minimum for direct and transitive security; low=0.1, medium=4, high=7, critical=9. Null/omission includes unknown scores.
low, medium, high, critical