{"uid":"cap_74tU1JLZxT3L1VBhhv2yr","slug":"salt19-dependency-upgrade-go-no-go-decision-engine-d4ce3cf7","name":"SALT19 Dependency Upgrade Go/No-Go Decision Engine","description":"SALT19 is an independent applied AI systems lab behind EvoMind governed cognition, the MCP-native Agent Utility Grid, the ARCS research community, AeroClear UAS flight intelligence, and practical software for real-world work.","url":"https://api.salt19.com/v1/dependency-upgrade-go-no-go","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"package":{"type":"string","maxLength":214,"minLength":1},"runtime":{"type":"string","maxLength":128},"framework":{"type":"string","maxLength":128},"constraints":{"type":"array","items":{"type":"string","maxLength":4000},"maxItems":32},"target_version":{"type":"string","maxLength":64,"minLength":1},"current_version":{"type":"string","maxLength":64,"minLength":1}}},"responseSchema":{"type":"json","example":{"score":0.84,"verdict":"GO","upgrade_verdict":"UPGRADE","breaking_changes":{"state":"NOT_PROVEN","version_change":"PATCH"},"recommended_tests":["Install/resolve the target dependency in the actual caller lockfile."],"runtime_compatibility":{"state":"NOT_PROVEN"},"security_implications":{"state":"SUPPORTED","target_osv_records":0,"current_osv_records":0},"peer_dependency_conflicts":{"state":"NOT_PROVEN"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.16","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.16/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.16","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.16","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_OxIM6NAEcKrIcWGj8lqal","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.16","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes a proposed package version upgrade and returns a scored go/no-go verdict covering breaking changes, security implications, runtime compatibility, and peer dependency conflicts.","exampleAgentPrompt":"Can you run a go/no-go analysis on upgrading the axios package from version 1.6.0 to 1.7.2 in a Node.js 20 environment with an Express framework — I need to know if there are breaking changes, security issues, or peer conflicts before I merge this?","exampleUseCases":[{"title":"Pre-merge dependency safety check","prompt":"Before I merge this PR, can you check whether upgrading lodash from 4.17.20 to 4.17.21 in our Node.js 18 app is safe — any breaking changes, CVEs, or peer conflicts I should know about?"},{"title":"Security-driven forced upgrade assessment","prompt":"Our security scanner flagged log4j 2.14.1 as vulnerable — can you evaluate upgrading to 2.17.1 in a Java 11 / Spring Boot environment and tell me if it's a go or no-go with a confidence score?"},{"title":"Framework migration dependency audit","prompt":"We're moving from React 17 to React 18 and I need a go/no-go on upgrading react-query from 3.39.3 to 4.36.1 — are there breaking changes or peer dependency conflicts I should handle first?"}],"resultDescription":"Returns a JSON object with a numeric confidence score (0–1), a GO or NO-GO verdict, an upgrade recommendation, and structured states for breaking changes (with version change type), runtime compatibility, security implications (with OSV record counts for both versions), peer dependency conflicts, and a list of recommended tests to validate the upgrade.","failureModes":["Missing required fields (package, current_version, target_version) return a 400 validation error","Unknown or private packages may result in NOT_PROVEN states across all dimensions with lower confidence scores","Highly unusual version strings may fail parsing and return an error","Overly long or malformed constraint strings may be rejected","Network or upstream registry timeouts may cause 503 responses"],"whenToPreferThis":"Choose this endpoint when an AI agent or CI/CD pipeline needs a structured, scored recommendation on whether to proceed with a specific dependency upgrade — especially when you need explicit signals on breaking changes, OSV security records, peer conflicts, and runtime compatibility in a single call. Prefer this over generic vulnerability scanners when you want an actionable GO/NO-GO verdict with a confidence score rather than raw advisory data.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:30:54.810Z","isFirstParty":false}