Tenuo has released safe-upgrade, an open-source dependency upgrade agent designed to mitigate risks in automated updates, such as breaking API changes or altered module formats that standard CI tests might fail to detect. The tool works within an isolated Git worktree, inspecting the repository and researching target releases to ensure sound results.
Product Launchessafe-upgradeTenuo
Tenuo releases safe-upgrade: An open-source agent for secure dependency upgrades
The agent's architecture relies on the separation of judgment, control flow, and authority. It utilizes Jev as a "System One Model" to provide typed probabilistic decisions based on repository evidence. LangGraph orchestrates the workflow, maintaining state and decisions across the process, while Tenuo provides security by issuing short-lived, task-scoped warrants to specific workers. This ensures that each component, such as the test author or the implementer, operates with only the minimum necessary permissions.
In practical use, safe-upgrade can perform assessments, propose migrations, and execute upgrades. When paired with a "patch model" (via OpenAI), it can propose repository-specific behavioral tests and source code changes to address complex compatibility issues. The process includes an independent verification step where separate workers confirm that the changes align with the repository's existing checks.
The tool is available via npm and GitHub. It supports various workflows, including integration with CI/CD pipelines like GitHub Actions to assess Dependabot or Renovate pull requests.
Sources
- Jev in practice: typed decisions, scoped authority (Hacker News Frontpage, 2026-09-23)
- safe-upgrade