Bu

Bumpgen – upgrade NPM packages using AI

Hacker News

Bumpgen – upgrade NPM packages using AI

Hey HN, we are building bumpgen ( https://github.com/xeol-io/bumpgen/ ) to remove the toil of fixing breaking changes during version bumps. bumpgen bumps your npm package version then generates the fixes to potential breaking changes. There were some interesting challenges we encountered using an LLM to fix breaking changes: [1] Finding the breaking changes → know how is a dependency used through the codebase [2] Knowing how to fix the a breaking change → know how the dependency has changed from one version to another [3] Understanding how the fix has modified existing behavior → know how the function the dependency is used in is used through the codebase We addressed challenge [1] and [2] by choosing to support Typescript first. The strong typing helps us identify the breaking changes with a version bump pretty well. We can then pass the type errors into the LLM to increase its fix accuracy. Challenge [3] is definitely the trickiest. We built an AST of the codebase that we then use to create a “plan graph” ( https://huggingface.co/papers/2309.12499 ) of the type error, the function it’s used in, and the functions calling it. This plan graph should tell us how a fix would need to be perpetuated throughout the codebase. At a high level bumpgen’s core loop is something like this: - build an AST to understand your code’s relationships - bump version and get type errors - combine the above to create a plan graph ( https://huggingface.co/papers/2309.12499 ) of how to fix the error and apply it to the rest of the codebase - prompt the LLM to step through the plan graph and fix each breaking change - validate the fixes with a rebuild We also built our own benchmark suite ( https://github.com/xeol-io/swe-bump-bench ) to test bumpgen’s accuracy. It is a set of repos with human commits for version bumps. We would run bumpgen on the prior commit then compare bumpgen’s PR to that of the human commit to determine success. Our latest benchmark sits around ~50% accuracy. Up next we want to better address challenge [2] by building embeddings for different dependency versions to give the LLM more context on the changes across versions. After that we will be releasing a GitHub app with some qol features such as configuring update cadences, etc before moving onto C# and Golang support. We covered a lot of our architecture and thought process for bumpgen, we would love to hear your thoughts and feedback in the comments!

Share card

Actual performance

20points
9comments
Made the leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: context, using, code · Missing: mac, agents, macos
71%71% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Missing: supports, reddit linkedin, podcasting
70%70% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
Hacker NewsMay not resonate with HN audience · Strong signals: exist, existing, ide · Missing: https docs, excited, just released
47%47% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
TrustMRRLess likely to generate early MRR · Missing: mobile apps, ios, personal
44%44% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
AppSumoMay struggle as an AppSumo deal · Missing: plus, platform, intuitive
38%38% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
14%14% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Missing: web3, chat, crypto
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Incorrect prediction on native model

Similar products

Se
See what other NPM packages everyone else is using35%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

See what other NPM packages everyone else is using

Hacker News67
Go
GoDoc for NPM Packages36%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

GoDoc for NPM Packages

Hacker News1
NP
NPM Packages-Outdated36%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

NPM Packages-Outdated

Hacker News2
np
npm addict – Your daily injection of npm packages26%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

npm addict – Your daily injection of npm packages

Hacker News5
Im
Implit – A CLI that catches AI-hallucinated NPM packages25%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Implit – A CLI that catches AI-hallucinated NPM packages

Hacker News1
Bu
Bundlephobia – find the cost of installing npm packages46%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Bundlephobia – find the cost of installing npm packages

Hacker News2
Pu
Publish npm packages with fewer screwups56%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Publish npm packages with fewer screwups

Hacker News1
Au
Audit NPM packages before installing41%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Audit NPM packages before installing

Hacker News1
Pa
Paid NPM Packages49%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Paid NPM Packages

Hacker News1
In
Instantly Search for NPM Packages40%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Instantly Search for NPM Packages

Hacker News4