Read the complete change surface

Inspect release notes, migration guides, removed APIs, default changes, transitive dependencies, supported runtimes, and known regressions. A version range in a manifest does not describe the behavior your application actually uses.

Locate calls to changed APIs and add tests around the application boundary. Lockfiles, generated clients, native extensions, and container bases may need coordinated updates.

  • Direct and transitive versions
  • Runtime support
  • Configuration defaults
  • Data-format changes

Observe the candidate

Build in a clean environment, run contract and integration tests, and compare logs, latency, memory, and error categories. Canary exposure should have a defined stop condition rather than relying on intuition.

Record why the version was selected and how it was verified. That note becomes evidence for the next upgrade and for incident triage.

Verification checkpoint

Rebuild from an empty cache, run the boundary tests, and compare operational measurements with the current release.