You ship. The lockfile ages. Point Looper at the repo. It flags outdated packages, known vulnerabilities, unused deps, and license risk on a schedule โ so the solo night is not a stall.
Pro is $19/mo for 10 loops. Two free loops, no card, if you want to try first.
A solo operator closes the laptop with packages that still have CVEs. Morning does not patch the unused dep. Looper is the loop that runs anyway.
Major, minor, and patch lag sits in package.json, Cargo.toml, requirements.txt, or go.mod. Nobody opened the upgrade.
The advisory landed. The lockfile did not. The next deploy still ships the hole.
Dead imports still install. The tree grows. The next person who clones it pays the cost.
Restrictive licenses and unmaintained packages (no updates in 12+ months) wait until a lawyer or a breach finds them.
Same cycle every run. You set the schedule. Looper treats the dependency tree as a living target, not a one-shot audit dump.
Read package.json, Cargo.toml, requirements.txt, or go.mod so the next pass has a baseline.
Look for outdated packages, known vulnerabilities, unused deps, restrictive licenses, and unmaintained packages.
Prioritize upgrades by risk and suggest the specific bump before a human reviews.
Check which upgrades still sit untouched. Keep the ones that landed. Refine the next pass.
Real numbers only. No card on free. Checkout can wait โ start from the dashboard.
2 loops. No card.
10 loops. The overnight default.
When more people share the loops.
When the org outgrows a small set of loops.
Pro is $19/mo for 10 loops. Wake up to risk-ranked upgrade notes on packages that sat all day.
Get Pro ยท $19/mo