Twelve production websites on one server, each with its own Composer dependency tree, and the oldest question in hosting: are they up to date, and is it safe to make them so? The dependency-currency gate answers it weekly and automatically — it inventories every vhost, checks each dependency tree against the PHP version that site's web server actually runs, queues the semver-safe updates for approval, and reports the breaking ones instead of applying them.
The legacy Drupal Automatic Updates API is gone. Audit branches, Composer, hosting constraints, and deployment workflows before the next security release.
A practical 2026 guide to auditing a legacy Drupal 9 site, using Drupal 10 as a controlled bridge, and deciding whether to upgrade to Drupal 11 or rebuild.