---
title: "Updates and CI"
description: "Update fixed Playstack package versions, reconcile owned output, and generate a review-first scheduled workflow."
tags: ["cli","updates","ci","pull-requests","automation"]
---

Package installation and ordinary artifact commands remain offline. `playstack update` is the explicit boundary where the CLI may invoke the repository's package manager and interact with a configured pull-request host.

## Preview and apply an update

```sh
npx playstack update --dry-run
npx playstack update
```

The CLI selects the package manager from the committed `packageManager` field or repository lockfile. It updates only installed `@playstack/*` dependencies and keeps their fixed versions aligned.

After the package-manager step, the CLI:

1. synchronizes managed Prisma, email, content, and translation artifacts;
2. refreshes the configured lint fragment and Skills corpus;
3. attempts safe three-way merges for ejected artifacts; and
4. reports conflicts without overwriting application-owned files.

## Open review branches

```sh
npx playstack update --pr
```

Pull-request mode requires a clean tracked worktree and a configured host adapter. It partitions changes by ownership:

| Review branch  | Contains                                                           |
| -------------- | ------------------------------------------------------------------ |
| Primary        | Fixed package versions and package-owned managed output.           |
| Ejected merge  | Clean application-owned merges, based on the primary branch.       |
| Conflict draft | One isolated artifact conflict without committed conflict markers. |

Security manifest flags label the affected review and always disable auto-merge. Clean ejected changes remain human-reviewed because the application owns their behavior.

## Configure scheduled updates

```json
{
  "updates": {
    "gitHost": "github",
    "schedule": "0 9 * * 1",
    "requiredCheck": "test",
    "autoMerge": false
  }
}
```

```sh
npx playstack ci init
```

`ci init` emits `.github/workflows/playstack-update.yml` from the committed policy. It records:

- the weekly cron schedule;
- the existing CI job required before merge; and
- whether eligible managed updates may auto-merge.

An existing workflow is never overwritten unless `--force` is explicit. The generated workflow runs the same reviewed update command rather than introducing a second update implementation.

## Doctor in ordinary CI

Scheduled updates and ordinary drift checks are separate concerns. Add the offline check to the repository's normal verification workflow:

```sh
npx playstack doctor --check
```

Interactive `playstack init` can offer that edit for an existing GitHub Actions job, but it prints the proposed change and asks independently before writing it.

For ownership behavior during an update, see [Ejection and merging](/docs/cli/ejection-merging).
