Check Python package requirements for updates with optional AI-powered analysis
Project description
req-update-check
A Python tool to check your requirements.txt file for package updates, with optional AI-powered changelog analysis and file caching for better performance.
Features
- Check for available updates in your requirements.txt and pyproject.toml files
- Show update severity (major/minor/patch)
- Display package homepages and changelogs when available
- AI-powered changelog analysis - Analyze upgrade safety with Claude, Gemini, OpenAI, or custom AI providers
- Codebase-aware recommendations - AI scans your code to provide specific, actionable advice
- Optional file caching for faster repeated checks
- Support for comments and inline comments in requirements.txt
- Ignores pre-release versions (alpha, beta, release candidates)
Installation
Basic Installation
Install from PyPI:
pip install req-update-check
Installation with AI Features
To use AI-powered analysis, install with AI providers:
# Install with all AI providers (Claude, Gemini, OpenAI)
pip install req-update-check[ai]
# Or install from source
git clone https://github.com/ontherivt/req-update-check.git
cd req-update-check
pip install -e ".[ai]"
Usage
Basic Usage
Check for updates without AI analysis:
req-update-check requirements.txt
AI-Powered Analysis
Analyze upgrade safety with AI (requires API key):
# Analyze a specific package with Claude (default)
export ANTHROPIC_API_KEY="sk-ant-..."
req-update-check requirements.txt --ai-check requests
# Analyze all outdated packages
req-update-check requirements.txt --ai-check
# Use a different AI provider
export GEMINI_API_KEY="..."
req-update-check requirements.txt --ai-check --ai-provider gemini
# Use OpenAI
export OPENAI_API_KEY="sk-..."
req-update-check requirements.txt --ai-check --ai-provider openai
Command Line Options
req-update-check [-h] [--no-cache] [--cache-dir CACHE_DIR]
[--ai-check [PACKAGE]] [--ai-provider {claude,gemini,openai,custom}]
[--ai-model MODEL] [--api-key API_KEY]
requirements_file
Arguments:
requirements_file: Path to your requirements.txt or pyproject.toml file
Note: pyproject.toml support requires Python 3.11+
General Options:
--no-cache: Disable file caching--cache-dir CACHE_DIR: Custom cache directory (default:~/.req-check-cache)
AI Analysis Options:
--ai-check [PACKAGE]: Analyze updates with AI (optionally specify package name, or analyze all if omitted). Will only display selected package.--ai-provider {claude,gemini,openai,custom}: Choose AI provider (default: claude)--ai-model MODEL: Override default model for the provider--api-key API_KEY: Provide API key directly (or use environment variables)
Example Output
Basic output:
File caching enabled
The following packages need to be updated:
requests: 2.28.0 -> 2.31.0 [minor]
Pypi page: https://pypi.python.org/project/requests/
Homepage: https://requests.readthedocs.io
Changelog: https://requests.readthedocs.io/en/latest/community/updates/#release-history
With AI analysis:
File caching enabled
The following packages need to be updated:
requests: 2.28.0 -> 2.32.5 [minor]
Pypi page: https://pypi.python.org/project/requests/
Homepage: https://requests.readthedocs.io
๐ค Analyzing with AI...
AI ANALYSIS:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
Safety: SAFE (Confidence: high)
Model: claude-3-5-sonnet-20241022
Tokens: 8,245 in / 1,823 out / 10,068 total
Recommendations:
1. Review the changelog for security fixes in versions 2.29.0-2.32.0
2. Test SSL certificate verification in your application
3. Update request timeout handling if using default timeouts
New Features:
โข Improved connection pooling performance
โข Better support for modern TLS versions
โข Enhanced cookie handling
Summary: This is a safe minor version upgrade with important security
fixes and performance improvements. No breaking changes detected in your
current usage patterns.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
AI-Powered Analysis Features
What Gets Analyzed
When you use --ai-check, the tool:
- Fetches changelogs from GitHub releases, direct changelog URLs, or package metadata
- Scans your codebase to find how you're using the package
- Sends to AI with context about your usage patterns
- Returns analysis with:
- Safety assessment (safe/caution/breaking)
- Breaking changes that affect your code
- Deprecations in your current usage
- Actionable upgrade recommendations
- Relevant new features
- Token usage statistics
Supported AI Providers
| Provider | Model | Cost/Analysis* | Setup |
|---|---|---|---|
| Claude (Anthropic) | claude-3-5-sonnet-20241022 | ~$0.05 | export ANTHROPIC_API_KEY="sk-ant-..." |
| Gemini (Google) | gemini-2.0-flash-exp | ~$0.01 | export GEMINI_API_KEY="..." |
| OpenAI | gpt-4o | ~$0.05 | export OPENAI_API_KEY="sk-..." |
| Custom | Your choice | Varies | Configure via config file |
*Estimated cost based on typical changelog and codebase size
API Key Setup
Option 1: Environment Variables (Recommended)
# For Claude
export ANTHROPIC_API_KEY="sk-ant-..."
# For Gemini
export GEMINI_API_KEY="..."
# For OpenAI
export OPENAI_API_KEY="sk-..."
Option 2: Command Line
req-update-check requirements.txt --ai-check --api-key "your-key-here"
Option 3: Config File (Coming in Phase 4)
# ~/.config/req-update-check/config.toml
[ai.api_keys]
claude = "sk-ant-..."
gemini = "..."
Caching
AI analysis results are cached for 24 hours to save on API costs. The cache is automatically invalidated when:
- Your codebase changes (files using the package are modified)
- 24 hours have passed
- You use
--no-cache
Using file Caching
The tool supports file caching to improve performance when checking multiple times. You can configure the cache storage:
req-update-check --cache-dir ~/.your-cache-dir requirements.txt
Requirements.txt Format
The tool supports requirements.txt files with the following formats:
package==1.2.3
package == 1.2.3 # with spaces
package==1.2.3 # with inline comments
# Full line comments
Note: Currently only supports exact version specifiers (==). Support for other specifiers (like >=, ~=) is planned for future releases.
Python API
You can also use req-update-check as a Python library:
from req_update_check import Requirements
from req_update_check.ai_providers import AIProviderFactory
# Basic usage without AI
req = Requirements('requirements.txt', allow_cache=False)
req.check_packages()
req.report()
# With AI analysis
provider = AIProviderFactory.create(
provider_name='claude',
api_key='sk-ant-...', # or set ANTHROPIC_API_KEY env var
)
req = Requirements(
'requirements.txt',
ai_provider=provider,
)
req.check_packages()
# Analyze specific package
req.report(ai_check_packages=['requests'])
# Or analyze all packages
req.report(ai_check_packages=['*'])
Development
To set up for development:
- Clone the repository
- Create a virtual environment:
python -m venv venv - Activate the virtual environment:
source venv/bin/activate(Unix) orvenv\Scripts\activate(Windows) - Install development dependencies:
pip install -e ".[dev,ai]"
Running Tests
# Run all tests
python -m unittest
# Run specific test file
python -m unittest tests.test_req_cheq
# Run with coverage
coverage run -m unittest discover
coverage report
coverage xml
Code Quality
# Check code style
ruff check .
# Format code
ruff format .
# Auto-fix issues
ruff check --fix .
Project Structure
src/req_update_check/
โโโ ai_providers/ # AI provider implementations
โ โโโ base.py # Abstract base class and AnalysisResult
โ โโโ claude.py # Claude (Anthropic) provider
โ โโโ gemini.py # Gemini (Google) provider
โ โโโ openai.py # OpenAI provider
โ โโโ custom.py # Custom/local provider
โ โโโ factory.py # Provider factory
โโโ ai_analyzer.py # Main analysis orchestrator
โโโ changelog_fetcher.py # Fetch changelogs from various sources
โโโ code_scanner.py # Scan codebase for package usage
โโโ prompts.py # AI prompt templates
โโโ formatting.py # Output formatting
โโโ auth.py # API key management
โโโ cache.py # File caching
โโโ core.py # Main Requirements class
โโโ cli.py # Command-line interface
โโโ exceptions.py # Custom exceptions
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
License
This project is licensed under the MIT License - see the LICENSE file for details.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file req_update_check-0.5.2.tar.gz.
File metadata
- Download URL: req_update_check-0.5.2.tar.gz
- Upload date:
- Size: 150.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
14763818637a27ed305b957ce288bf333bed92b5ea311c78557472eb3673b5f8
|
|
| MD5 |
6c340d07fe7e77f77deabcf48a80d266
|
|
| BLAKE2b-256 |
5cbcde9bddba54a0c73d767f2f09c15de4c855a1c2734a974f3499d8e6335a06
|
Provenance
The following attestation bundles were made for req_update_check-0.5.2.tar.gz:
Publisher:
release-please.yml on ontherivt/req-update-check
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
req_update_check-0.5.2.tar.gz -
Subject digest:
14763818637a27ed305b957ce288bf333bed92b5ea311c78557472eb3673b5f8 - Sigstore transparency entry: 868821438
- Sigstore integration time:
-
Permalink:
ontherivt/req-update-check@371fc52c39cd4b8fc1afe84fce2b91cc467d0fa7 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/ontherivt
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-please.yml@371fc52c39cd4b8fc1afe84fce2b91cc467d0fa7 -
Trigger Event:
push
-
Statement type:
File details
Details for the file req_update_check-0.5.2-py3-none-any.whl.
File metadata
- Download URL: req_update_check-0.5.2-py3-none-any.whl
- Upload date:
- Size: 36.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b612bd02c52865c2fe718f51bc42c017273908f1a2e65ec3eee3abdba7c8d6c9
|
|
| MD5 |
6e3e3fb5c3e29008f38d1e73cc330b64
|
|
| BLAKE2b-256 |
bb0724120b54bcda6e14f78f3433dcc244e8d73d16330d9ded18ed7cdb015070
|
Provenance
The following attestation bundles were made for req_update_check-0.5.2-py3-none-any.whl:
Publisher:
release-please.yml on ontherivt/req-update-check
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
req_update_check-0.5.2-py3-none-any.whl -
Subject digest:
b612bd02c52865c2fe718f51bc42c017273908f1a2e65ec3eee3abdba7c8d6c9 - Sigstore transparency entry: 868821443
- Sigstore integration time:
-
Permalink:
ontherivt/req-update-check@371fc52c39cd4b8fc1afe84fce2b91cc467d0fa7 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/ontherivt
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-please.yml@371fc52c39cd4b8fc1afe84fce2b91cc467d0fa7 -
Trigger Event:
push
-
Statement type: