Everything in my project is years out of date. How do I update it?

Also searched as: Outdated dependencies · npm outdated dependencies · npm package deprecated · Deprecated package Python · Outdated dependencies OWASP

Updated 3 October 2026

Short answer

Get it running exactly as it is first, on the old versions, so you have a working baseline. Then update in small steps, in order: the runtime (Node, Python, PHP) to a supported version, then the main framework, then everything else, testing after each step. Replace packages that have been abandoned instead of forcing them forward. Updating everything at once is how a stale project becomes a broken one.

What's the problem

The project hasn't been touched in years. Tools warn that packages are deprecated, security scans list dozens of vulnerabilities, hosting no longer supports its runtime, and every attempt at a quick upgrade breaks it.

Why it happens

  • Everything moves at once. The language, the framework and hundreds of packages all release new versions, some with breaking changes. A project that stands still falls behind on all of them together.
  • Updates depend on each other. A new framework needs a newer language version, which some old packages don't support, which forces their replacement.
  • Abandoned packages don't come along. Some packages simply stop being maintained, and no newer version will ever support your new framework.
  • Old dependencies carry known vulnerabilities. OWASP ranks software supply chain failures third in its current Top 10.

How to fix it

  1. Get it running on the old versions and write down how. See the project only runs on an old version of Node.
  2. Put tests around the flows that matter, so you'll know when an update breaks something.
  3. List what's outdated with your package manager (npm outdated, pip list --outdated, composer outdated).
  4. Update the runtime to a supported long-term-support version, one major version at a time.
  5. Update the main framework, one major version at a time, following its official upgrade guide.
  6. Update the remaining packages in small groups, testing between each.
  7. Replace abandoned packages with maintained alternatives, or remove them if you can.
  8. Then keep up: small, regular updates are cheap. Years of them at once is a project.

When to call Preventionlabs

If the project is small and each step is a few fixes, work through it steadily. Call us when it's years behind on everything, the chain of upgrades keeps breaking, or nobody understands the code well enough to know what a change affects. Getting an app to build and start on maintained dependencies, deployed in your own hosting account, is the first thing a resurrection delivers.

Submit your project for a free assessment

Free assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.

Sources

  1. npm: npm outdatedofficial docsThis command will check the registry to see if any (or, specific) installed packages are currently outdated.
  2. OWASP: OWASP Top 10:2025security standards bodyA03:2025 - Software Supply Chain Failures
  3. Node.js: Node.js Releasesofficial docsProduction applications should only use Active LTS or Maintenance LTS releases.
  4. Martin Fowler: Strangler Figsoftware engineering referenceWhat this approach does do is make both investment and returns occur gradually and visibly
← All of It used to work