Skip to main content

taze 🥬

Keep your Python dependencies fresh.

Inspired by taze, this is the Python-native version: the same safe-by-default CLI workflow, adapted for PyPI, PEP 440, Python project metadata, and GitHub Actions.


Features

  • Checks all dependencies against PyPI in parallel
  • Shows the bump level (patch / minor / MAJOR) with colors
  • Displays release age for both the current and latest version
  • Supports pyproject.toml (PEP 508, PEP 735, uv, Poetry, PDM, and Hatch) and requirements*.txt
  • Writes updated version constraints back to the file (-w)
  • Detects uv, Poetry, PDM, and Pixi before installing (-i)
  • Interactive package selection (-I)
  • Recursive monorepo scanning (-r)
  • Pre-release support (newest / next mode)
  • Regex/glob filtering for include / exclude, including version selectors such as requests@2
  • Checks GitHub Actions refs with tag or SHA-preserving writes
  • JSON output for agents and CI, with optional fail-on-outdated status
  • Safe PEP 440 range resolution, a local TTL cache, maturity periods, and per-package policies

Installation

uv tool install taze
# or
uvx taze
# or
pip install taze

Usage

taze [mode] [options]

Modes

Mode What it shows
default Latest stable release allowed by the declared PEP 440 range
major Latest stable release, including major changes
minor Latest stable release in the current major version
patch Latest stable release in the current major/minor version
latest Alias for major
stable Range-safe stable updates
newest All updates including pre-releases
next Same as newest

Examples

# Check everything in the current directory
taze

# Only show minor and patch updates
taze minor

# Write patch updates back to pyproject.toml
taze patch -w

# Write all updates and run uv sync
taze -w -i

# Interactive checkbox menu (↑/↓, space, a, → version, Enter, Esc)
taze -I

# Include pre-releases
taze newest

# Scan all subdirectories (monorepo)
taze -r

# Only check specific packages
taze -n requests,httpx

# Skip packages matching a pattern
taze -x /^pytest/

# Skip only one version range, not the whole package
taze -x requests@3

# Do not upgrade releases published in the last two weeks
taze --maturity-period 14

# Include exact == pins (they are skipped by default)
taze -l

# Sort by largest update first
taze --sort diff-desc

# Machine-readable JSON output
taze --json

Options

  -w, --write              Write updates back to file
  -i, --install            Install after writing (implies -w)
  -u, --update             Alias for --install
  -I, --interactive        Choose which packages to update interactively
  -r, --recursive          Scan subdirectories for pyproject.toml / requirements*.txt
      --ignore-paths <glob> Comma-separated glob paths to skip with --recursive
      --ignore-other-workspaces / --include-other-workspaces
                            Skip nested repositories and workspaces (default: skip)
  -a, --all                Show up-to-date packages too
  -n, --include <deps>     Only check these packages (comma-separated or /regex/)
  -x, --exclude <deps>     Skip these packages (comma-separated or /regex/)
  -C, --cwd <path>         Working directory
  -s, --silent             No output
  -v, --version            Show version
      --sort <type>        Sort output: name-asc | name-desc | diff-asc | diff-desc
      --fail-on-outdated   Exit with code 1 if any outdated dependencies are found
  -l, --include-locked     Include exact == version pins
      --maturity-period <n>
                            Require a release to be at least n days old
      --maturity-period-exclude <deps>
                            Bypass the maturity period for selected packages
      --config <path>      Read settings from a taze.toml file
      --concurrency <n>    Number of concurrent PyPI requests (default: 10)
      --json               Machine-readable JSON output (updates only; use -a for all)
      --force, -f          Bypass the local metadata cache
      --retry <n>          Retries after failed registry requests
      --no-retry           Disable registry retries
      --request-timeout <s>
                            Registry request timeout in seconds
      --github-actions/--no-github-actions
                            Check workflow and composite-action references
      --github-actions-style <auto|tag|sha>
                            Preserve or choose action reference style
      --github-actions-pin  Pin GitHub Actions to their commit SHA even if
                            already up to date (implies sha style)

Output

  📦  pyproject.toml  /home/user/myproject/pyproject.toml

  dependencies  3 outdated
    packaging  ~8mo  >=25.2     →  >=26.2     ~3mo  MAJOR
    rich       ~4mo  >=14.0.0   →  >=15.0.0   ~3d   MAJOR
    typer      ~6mo  >=0.25.7   →  >=0.26.7   ~3d   minor

  group:dev  1 outdated
    ruff       ~8mo  >=0.14.1   →  >=0.15.19  ~1d   minor

  Run taze -w to write 4 update(s) to pyproject.toml

The age columns show how old the current pinned version is and how recently the latest version was released — green for < 4 weeks, yellow for < 6 months, red for older.


Supported file formats

File Section
pyproject.toml [project] dependencies
pyproject.toml [project.optional-dependencies.*]
pyproject.toml [dependency-groups.*] (PEP 735)
pyproject.toml [tool.uv.dev-dependencies]
pyproject.toml [tool.uv.constraint-dependencies]
pyproject.toml [tool.poetry.dependencies]
pyproject.toml [tool.poetry.group.*.dependencies]
pyproject.toml [tool.pdm.dev-dependencies.*]
pyproject.toml [tool.hatch.envs.*.dependencies]
requirements*.txt Standard pip format
.github/workflows/*.yml / action.yml Versioned uses: refs

Monorepos

taze -r finds supported dependency files under the working directory. It skips virtual environments, build/cache directories, and nested repositories/workspaces by default. Use --ignore-paths examples/**,vendor/** for additional exclusions, or --include-other-workspaces to deliberately scan nested workspaces.

Project names declared in workspace pyproject.toml files are recognised as local packages and are not looked up on PyPI.

Configuration

Place options in taze.toml or in the [tool.taze] table of pyproject.toml. Precedence is CLI, TAZE_-prefixed environment variables, taze.toml, then pyproject.toml.

[tool.taze]
recursive = true
ignore_paths = ["examples/**", "vendor/**"]
maturity_period = 7
maturity_period_exclude = "internal-tools"
include_locked = false

[tool.taze.package_mode]
django = "minor"
"/pytest-.*/" = "patch"
setuptools = "ignore"

package_mode accepts every mode listed above, plus ignore. Exact package names, * globs, and slash-delimited regular expressions are supported. The cache lives at $XDG_CACHE_HOME/taze/pypi.json (or ~/.cache/taze/pypi.json) for 30 minutes; --force bypasses it.

GitHub Actions use the GitHub REST API. Set GITHUB_TOKEN or GH_TOKEN to avoid unauthenticated API limits. Branch refs, local actions, Docker actions, and non-v tags are left untouched.

Installation

taze -i writes updates, then chooses an installer from the project metadata: uv sync, poetry install, pdm install, or pixi install. -u is an alias for -i.


License

MIT

Release files for taze 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for taze 0.5.0
File Size Uploaded
taze-0.5.0.tar.gz 36.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for taze 0.5.0
File Interpreter ABI Platform
taze-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 81.1 kB

Release files / taze-0.5.0.tar.gz

Download URL taze-0.5.0.tar.gz
Size 36.2 kB
Tags Source
SHA-256 checksum
How to use checksums
199e9a0ae6ee9dcf7fef4ef9f301d250db99dbe7e7772ce8ca0f42ad64588373
BLAKE2b-256 checksum
How to use checksums
c6e1a16f8b4dd9688696c4503085fd7c88802b8073bb0307ea40821d1c4b596b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.16 {"installer":{"name":"uv","version":"0.12.16","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / taze-0.5.0-py3-none-any.whl

Download URL taze-0.5.0-py3-none-any.whl
Size 44.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b5fff973e45da64f986268a93fea62c2d519f15051e47820b1f3fa4651ca2844
BLAKE2b-256 checksum
How to use checksums
7326c57d18db4964bfca956669e5e93887747db976d44f99cdd86a9da5d2addf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.16 {"installer":{"name":"uv","version":"0.12.16","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.5.0 This release

2 release files

0.3.0

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page