livecheck
Tool for overlays to update ebuilds. Inspired by the MacPorts port subcommand of the same name
and nvchecker.
Internal workings
The script searches for new versions at every SRC_URI location of the ebuild that refers to the
package, using logic for GitHub, PyPI, PECL, and other hosts, or the configuration in the
livecheck.json file within the same package directory. Vendor archives and signature or checksum
files are skipped. The first remaining entry is always consulted, and a later entry is consulted
when its URL includes both the package name and the ebuild version. The highest version found
across the locations is selected, and a location that is not updated upstream does not hide a
newer version published at another one. When no location reports a version, metadata.xml,
HOMEPAGE, Repology, and directory listings are tried in turn. The ebuild is automatically updated
if --auto-update is passed.
It is recommended to use OAuth tokens for both Github and GitLab to avoid rate limiting problems
with the REST API. Use your secret storage to store github.com, bitbucket.org or gitlab.com
tokens with the livecheck user. See keyring to manage tokens.
Example: storing credentials
secret-tool store --label="Password for 'livecheck' on 'bitbucket.org'" service bitbucket.org username livecheck
Installation
On Gentoo, add my overlay and install:
eselect overlay enable tatsh-overlay
emerge --sync
emerge livecheck
Command line usage
Usage: livecheck [OPTIONS] [PACKAGE_NAMES]...
Options:
-a, --auto-update Rename and modify ebuilds.
-d, --debug Enable debug logging.
-D, --development Include development packages.
--dist-github-release TEXT GitHub release tag to upload vendor dist
archives under.
--dist-github-repository TEXT
GitHub `owner/repo` to upload vendor dist
archives to as release assets.
--dist-force-upload Force rebuild and re-upload of vendor dist
archives even when present.
-e, --exclude TEXT Exclude package(s) from updates.
-g, --git Use git and pkgdev to make changes.
-H, --hook-dir Run a hook directory scripts with various parameters.
-k, --keep-old Keep old ebuild versions.
-p, --progress Enable progress logging.
--package-manager [npm|pnpm|yarn]
Package manager to use for Node.js packages.
-W, --working-dir DIRECTORY Working directory. Should be a port tree root.
--help Show this message and exit.
Uploading vendor dist archives to GitHub releases
When --auto-update regenerates a vendor archive (Composer, Go modules, Maven, Node modules, or
NuGet packages), the file is normally written only into DISTDIR. Pass both
--dist-github-repository owner/repo and --dist-github-release tag to additionally publish the
archive as an asset of that release. Per-package overrides may also be set in livecheck.json with
the keys dist_github_repository and dist_github_release.
By default the asset is skipped entirely (no rebuild, no upload) if a release asset with the
expected filename is already present; pass --dist-force-upload to rebuild and replace it. When
the release does not exist, livecheck creates it as a draft and logs a warning instructing you
to publish it from the GitHub UI so Portage can fetch the assets.
Heuristic update detection
This package can do automated lookups based on commonly used hosts. Currently:
- Bitbucket
- Davinci products
- Github archives
- Github commit hashes
- Github releases
- GitLab releases
- Hex-Rays for IDA Free
- JetBrains products
- NuGet
- PECL
- Packages from Yarn and NPM
- Perl CPAN
- PyPI
- Raphnet
- Repology
- RubyGems
- SourceHut releases / commit hashes
- SourceForge
This works as long as the version system is usable with Portage's version comparison function. For anything else, see Package configuration.
Package configuration
For packages that will not work with heuristic checking, a configuration file named livecheck.json
can be placed in the directory alongside the ebuild.
Configuration keys
branch- string- The GitHub branch name to use for commits.composer_packages- boolean - Download composer vendor modules.composer_path- path - Where is 'composer.json' located (need composer_packages).crates- boolean - Build a Rust dependency archive with Cargo using versions fromCargo.lock.crates_path- path - Source subdirectory withCargo.tomlandCargo.lock(requirescrates).dist_github_release- string - Per-package override for--dist-github-release.dist_github_repository- string - Per-package override for--dist-github-repository(owner/repo).dotnet_packages- boolean - Build a NuGet packages vendor archive (-nuget.tar.xz).dotnet_project- path - Project or solution file (.csproj/.sln) used bydotnet restore.maven_packages- boolean - Download Maven dependencies.maven_path- path - Where is 'pom.xml' located (need maven_packages).development- bool - Include development packages.gomodule_packages- boolean - Download go vendor modules.gomodule_path- path - Where is 'go.mod' located (need gomodule_packages).jetbrains_packages- boolean - Update internal ID.keep_old- boolean - Keep old ebuild versions.no_auto_update- boolean - Do not allow auto-updating of this package.nodejs_packages- boolean - Download nodejs node_modules.nodejs_path- path - Where is 'package.json' located (need nodejs_packages).nodejs_package_manager- string - Package manager to use for Node.js packages [npm|pnpm|yarn] (defaults to npm)nodejs_omit_dev- boolean - Leave the development dependencies out of thenode_modulesarchive (need nodejs_packages). Only for ebuilds that do not run a build step.sha_source- string - Url to get the sha value.stable_version- string - Regular expression to determine if it is a stable version.sync_version- string - Category and ebuild with version to sync.transformation_function- string - Function to use to transform the version string. Currently onlydotizeis supported. Others are for internal use.type- string - Only onenone,davinci,regex,directory,changelog,commit,repologyorchecksum.
Use the pattern to adjust the version using a regular expression:
pattern_version- string - The pattern string.replace_version- string - The replacement string.
Only when type is regex, directory, or changelog:
url- URL of the document or directory listing to scan for versions. Required.
Example for type changelog:
{
"type": "changelog",
"url": "https://raw.githubusercontent.com/standard/standard/refs/heads/master/CHANGELOG.md"
}
Only when type is regex:
regex- string - The regular expression to use. Required.
Only when type is repology:
package- string - The package to search in repology. Required.
Hook directory
The hooks directory structure is subdivided into actions, currently post and pre. Within each
action directory there can be several scripts that are executed in order by name.
Arguments
- Root portage directory, e.g.
/var/db/repos/gentoo. - Category and package name, e.g.
dev-lang/php. - Previous version, e.g.
8.2.32-r2. - New version, e.g.
8.2.33. - SHA hash of the old version. Optional.
- SHA hash of the new version. Optional.
- Date associated with the hash. Optional.
Development use
Creating new downloads
Rust crate archives use the crates setting in a package's livecheck.json:
{
"crates": true
}
Cargo must be installed, and upstream sources must provide Cargo.toml and Cargo.lock.
Set crates_path when the Cargo project is in a source subdirectory. Dependencies are downloaded
with cargo vendor --locked --versioned-dirs; Git and alternative registry dependencies are
currently unsupported. A missing or outdated lock file aborts the update.
Configure the ebuild to fetch ${P}-crates.tar.xz from your dist server instead of individual
CARGO_CRATE_URIS, and remove its old CRATES list. The generated archive uses
cargo_home/gentoo/ under WORKDIR, as expected by cargo_src_unpack. Livecheck writes the archive
to DISTDIR using the same compression and optional GitHub upload helpers as other vendor archives.
Post-update hooks can upload the archive to a custom dist server.
There are 2 types of downloads: file and latest commit (currently only Git is supported) and this is evident from the first download URL of the ebuild itself.
-
To download a file, a search is performed by version/tag, and optionally you can include the commit of said version, including all the results in a list so that the highest one can be selected, according to the search criteria or limit.
-
To locate the last commit of an ebuild, we need the SHA of the commit and the date. This is necessary to be able to adjust the name of the ebuild using the a.b.c_pYYYYMMDD version as a scheme. If a different SHA is detected the version is updated.
Set up PYTHONPATH
As root, set the environment variable PYTHONPATH to include where the livecheck module is
located. Use python -m livecheck instead of livecheck to execute commands.
With a virtualenv
Run uv sync --all-groups --all-extras to set up a virtualenv.
Fully copy /etc/portage to the root of your virtualenv. Then you must fix make.profile. Also
consider making changes in repos.conf if necessary.
Example:
. .venv/bin/activate
uv pip install keyrings-alt
sudo cp -R /etc/portage "${VIRTUAL_ENV}/etc/"
sudo chown -R "${USER}:" "${VIRTUAL_ENV}/etc/portage"
ln -sf "$(readlink -f /etc/portage/make.profile)" "${VIRTUAL_ENV}/etc/portage/make.profile"
Metadata
Release files for livecheck 0.2.8
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| livecheck-0.2.8.tar.gz | 152.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| livecheck-0.2.8-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 250.1 kB
Release files / livecheck-0.2.8.tar.gz
| Download URL | livecheck-0.2.8.tar.gz |
|---|---|
| Size | 152.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
24029306ceb781604abd13d938fb8c1ba6941a24428ebe5588a0f0243f2dbb2f
|
|
BLAKE2b-256 checksum How to use checksums |
7edf69a3b77ad78b012a16239726c667ada0ee14114631e412da141c1143ec50
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.
Transparency logRelease files / livecheck-0.2.8-py3-none-any.whl
| Download URL | livecheck-0.2.8-py3-none-any.whl |
|---|---|
| Size | 98.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4888d0f448e7ec53ffbfe7bb590a7103634db102a7901a8f9fd300c73896e2e9
|
|
BLAKE2b-256 checksum How to use checksums |
f1a102a7afb22c2a3908934a983d1455818fc18b4e8774bcb2830180aca0f8be
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.
Transparency log