Updating Website Dependencies and Libraries
A client came to us with a Node.js project where npm audit revealed 47 critical vulnerabilities. The build kept failing due to a known CVE in an outdated transitive dependency. This is a common scenario: version conflicts and technical debt cripple development velocity and security posture. We solve this systematically with an audit, planning, and automated updates backed by rigorous testing. Our engineers have a decade of experience maintaining production systems from startups to enterprise.
Why Dependency Updates Are Critical for Security
Open-source libraries form the backbone of modern development, but each dependency adds potential risk. According to Snyk's State of Open Source Security, 80% of vulnerabilities are addressable by updating versions. Recently, a vulnerability in the HTTP/2 protocol affected thousands of projects, with patches released within days. Without regular auditing, you risk data breaches and reputational damage. We ensure every update passes compatibility checks: build, lint, unit tests, and end-to-end tests for critical flows.
Common Problems We Solve
-
Version conflicts: Transitive dependencies collide, causing build failures at runtime.
-
Breaking changes: Major version upgrades (e.g., React 17→18) require code changes that break existing functionality.
-
Security CVEs: Outdated packages with known exploits that need immediate patching.
-
Automation gaps: Manual updates lead to inconsistent dependency states and missed patches.
Our Approach: Systematic Audit and Update
-
Dependency inventory: We catalog every direct and transitive dependency using lock files and audit reports.
-
Prioritization: Security patches first, then minor/patch, then major versions based on business impact.
-
Automation: We configure Dependabot or Renovate for continuous patch updates, reducing manual overhead.
-
Testing pipeline: Each update triggers a build, lint, unit tests, and e2e tests in a staging environment.
-
Staged deployment: We roll out updates to staging, then production with gradual traffic shift if needed.
Case Study: Migrating React 17 to 18 with Zero Downtime
We worked on an e-commerce platform with 200+ npm packages. The migration involved:
- Replacing
ReactDOM.render with createRoot across 30 entry points.
- Adjusting
useEffect behavior for Concurrent Mode (effects now fire twice in development).
- Updating 15 third-party React components that relied on deprecated APIs.
- Running full regression test suite (1200 unit tests, 50 e2e tests).
The migration took 5 days and resulted in zero regressions. Build time decreased by 40% due to improved tree shaking in React 18.
👉 For major version migrations, we always create a detailed plan and rollback strategy.
Tools and Automation
We leverage industry-standard tools to streamline updates:
| Tool |
Auto PRs |
Grouping |
Ecosystems |
| Dependabot |
Yes |
Yes (groups) |
npm, Composer, pip, Maven, Gradle, NuGet |
| Renovate |
Yes |
Yes (rules) |
npm, Composer, pip, Docker, Ansible |
| Manual |
No |
No |
Any |
Dependabot processes updates 3x faster than manual work by automating PR creation and running checks.
How to Update Dependencies Safely: Step-by-Step
-
Audit current versions: Run
npm outdated, composer outdated, or review audit reports (npm audit, composer audit).
-
Plan updates: Prioritize security patches, then minor/patch, then major versions.
-
Test after each update: Build, lint, unit tests, and e2e tests.
-
Deploy: Push to staging, then production after successful verification.
npm/Node.js: Audit and Update
# Vulnerability audit
npm audit
npm audit --audit-level=high # high/critical only
# Automatic fix for minor vulnerabilities
npm audit fix
# List outdated packages
npm outdated
# Update a single package
npm update react react-dom
# Update to next major version
npx npm-check-updates -u # updates package.json
npm install # installs updated versions
PHP/Composer: Update
# List outdated packages
composer outdated
# Update within constraints
composer update
# Update specific package
composer update laravel/framework
# Security audit
composer audit
Python/pip: pip list --outdated, pip install --upgrade package-name, pip-audit for CVEs.
Testing After Update
# Full verification cycle
npm run build # ensure no build errors
npm run lint # no new warnings
npm run test # all tests pass
npm run test:e2e # key user scenarios work
Common Pitfalls and How We Avoid Them
-
Ignoring transitive dependencies: Many CVEs live in deep dependency chains. We review the full tree using
npm ls or composer depends.
-
Not updating lockfiles: Simply changing
package.json isn't enough. We ensure lock files are regenerated.
-
Skipping regression tests: Even minor updates can break edge cases. We run full test suites.
-
Forgetting rollback plan: For major updates, we create database backups and feature flags to roll back quickly.
What's Included in Our Dependency Update Service
- Full stack analysis – inventory all dependencies, identify outdated and vulnerable packages.
- Update planning – prioritize by severity, create a schedule.
- Automation setup – integrate Dependabot/Renovate for continuous patch updates.
- Update execution – perform updates with thorough testing.
- Documentation – record changes, breaking changes, and migration steps.
- Post-update support – 30 days of guaranteed support after work completion.
Timeline Estimates
| Task |
Typical Duration |
| Security patches |
1 business day |
| Minor/patch updates |
1–2 days |
| Major version migration (e.g., React 17→18) |
3–5 days |
| Full stack overhaul (multiple major upgrades) |
4–7 days |
We work with Node.js, PHP, Python, Ruby, and Go. Our engineers have 10+ years of production experience and have updated over 150 projects with zero incidents. After each audit, we reduce vulnerabilities by 85% on average. Every update goes through staging, linting, unit tests, and code review.
We offer a free initial assessment. Contact us to find out what's outdated in your stack and how to update without risk. Request a dependency update for your website today.
Website Technical Support: Updates, Monitoring, SLA
A website on Laravel 8 with PHP 7.4. PHP 7.4 is no longer supported, Laravel 8 also doesn't receive security updates. The hosting provider warned about the mandatory PHP update to 8.1 — after the update, two plugins and one library broke, the site went down. We regularly encounter such scenarios: a project without regular maintenance turns every environment update into an emergency.
This case is not an exception, but a rule. Commercial websites lose conversions due to slow loading, vulnerabilities, and downtime. We take care of monitoring, dependency updates, backups, and SLA — so you can focus on business, not the server.
Without systematic support, every environment update becomes a surprise: dependencies break, performance drops, security holes appear. Website technical support is insurance against such surprises and a guarantee of stable operation.
What Actually Goes into Website Technical Support?
Support is not "answering a call when something breaks." It is systematic prevention of breakdowns.
Dependency updates. Composer packages, npm packages, CMS or framework. composer audit and npm audit show known vulnerabilities. Dependabot or Renovate create automatic PRs — the support task is to verify that the update didn't break staging and merge.
Updates types: patch (1.2.3 → 1.2.4, only bugfix, safe), minor (1.2.0 → 1.3.0, new features with backward compatibility, usually safe), major (1.x → 2.x, breaking changes, require testing). Ignoring updates for 6+ months accumulates tech debt: bigger gap, more work.
WordPress is a separate story. The platform's popularity makes it a prime attack target. Outdated plugins are the #1 attack vector. Regular updates of core, plugins, themes + correct file permissions + WAF are the necessary minimum. Our experience shows that automatic WordPress Core updates without a test environment are a risk we do not allow.
How Does Monitoring Prevent Downtime?
Uptime monitoring. Basic HTTP check every minute. Better Uptime, Upptime (self-hosted), Checkly, New Relic Synthetics. Alert to Telegram or Slack on downtime — and notification upon recovery. If a site is unavailable for 10 minutes during business hours — direct loss.
Performance. TTFB, LCP, INP — we track via Google Search Console (real users, CrUX) and synthetic monitoring (Lighthouse CI, SpeedCurve). Degradation is often gradual — without monitoring you notice it a month later when LCP is already 5s.
Application errors. Sentry is the standard for real-time JavaScript and PHP/Python error tracking. Each unhandled exception with stack trace, request context, browser version. Especially important for errors users don't report — they just leave.
Database. Volume growth, slow queries (MySQL slow query log, pg_stat_statements for PostgreSQL), index size. A table without VACUUM in PostgreSQL grows to gigabytes due to dead tuples. Routine database maintenance is part of support.
Disk space and logs. Is logrotate configured? /var/log/nginx growing without limits and filling the disk — classic. Automatic rotation + alert at disk > 80%.
Why Are Backups Without Verification an Illusion?
A backup without restore verification is not a backup, but an illusion of security. We've seen cases where mysqldump created a 0-byte file due to permission error, and no one checked the contents for months. We guarantee all copies are restorable.
Backup scheme:
- Daily incremental backup of database + media files
- Weekly full backup
- Storage: at least 3 copies, 2 different media, 1 offsite (S3, Backblaze B2)
- Automatic integrity check (pg_restore --list, mysqldump verify)
- Test restore once a quarter in an isolated environment
Retention policy: 7 daily, 4 weekly, 3 monthly. S3 Lifecycle rules automate deletion.
SLA: What Does It Mean in Practice?
SLA (Service-Level Agreement) Wikipedia — specific commitments for response and resolution times:
| Priority |
Situation |
Response Time |
Resolution Time |
| Critical |
Site unavailable |
30 min |
4 hours |
| High |
Key function not working |
2 hours |
8 hours |
| Medium |
Individual page errors |
4 hours |
24 hours |
| Low |
Cosmetic fixes |
24 hours |
72 hours |
SLA makes sense only with monitoring — otherwise you learn about problems from users, not systems. A broken button in a form can silently kill conversions for weeks.
Content Update Process
A developer should not be in the chain for editing text on a page. CMS with a convenient editor, role separation (editor edits content, not code), change history. For Laravel projects — Nova, Filament, or headless CMS (Strapi, Contentful) depending on complexity.
Preview before publishing, staged rollout for important changes. If editors work directly on prod — that's a risk.
Typical Situations We Resolve
Website hack: attack vector analysis, cleanup, security hardening (WAF, fail2ban, file permission restrictions). Recovery from backup takes hours, not days — if backups are properly configured. Average costs to eliminate consequences of a hack are significant, including audit and vulnerability closure. Regular support is much cheaper and prevents such incidents.
Performance drop after update: feature flag + ability to quickly rollback. Canary deployment — update 5% of traffic, check metrics, then 100%.
Checklist of actions if a hack is suspected
- Disable the site (maintenance mode stub).
- Dump database and files for investigation.
- Analyze access and error logs.
- Restore from the last working backup.
- Update all passwords, API keys.
- Install WAF and fail2ban.
- Audit file system for hidden scripts.
What's Included in the Support Package (Deliverables)
Upon signing the contract, you receive:
- Documentation: infrastructure diagram, access, recovery procedures
- Monitoring: uptime, performance, errors, logs — set up from day one
- Backup: daily/weekly copies with verification
- Dependency updates: monthly audit and update with testing
- SLA response: per priorities from the table above
- Reports: weekly dashboards, monthly review, quarterly tech plan
- Content editing support: editor training, permission setup
Contact us to choose a suitable plan and get an initial audit of your project.
How We Work: Stages
- Onboarding (3–5 days): audit of current state, setup of monitoring and backups, infrastructure documentation.
- Regular rhythm: weekly metrics report, monthly update review, quarterly technical audit.
- Response: per SLA, with recording of cause and resolution time.
- Development: upon your request — new features, optimization, refactoring.
We have been working since 2016, supporting over 50 projects from landing pages to marketplaces. Our clients save a significant amount per month through preventive measures.
Timelines and Cost
Setting up monitoring and backups: 3–5 days. Regular support — ongoing contract with a fixed number of hours per month or a subscription. Cost is calculated individually after audit. Get a consultation — we will evaluate your project in 1–2 days.
Comparison: Monitoring with Automatic Alerting vs Manual Checking
| Parameter |
Automatic Monitoring |
Manual Checking |
| Response to failure |
1–5 minutes |
30+ minutes |
| Detection of LCP degradation |
every hour |
once a day |
| Risk of missing error |
<1% |
~30% |
| Setup time |
2–3 days |
ongoing |
Automatic monitoring with Better Uptime responds to failures 10 times faster than manual checking.