🥬 Keep your Python deps fresh
Project description
taze 🥬
Keep your Python dependencies fresh.
Inspired by taze for Node.js — ported to the Python ecosystem with support for pyproject.toml and requirements.txt.
Features
- Checks all dependencies against PyPI in parallel
- Shows the bump level (patch / minor / MAJOR) with colors
- Displays release age for both the current and latest version
- Supports
pyproject.toml(PEP 508, PEP 735, uv, PDM, Hatch) andrequirements*.txt - Writes updated version constraints back to the file (
-w) - Detects uv, Poetry, PDM, and Pixi before installing (
-i) - Interactive package selection (
-I) - Recursive monorepo scanning (
-r) - Pre-release support (
newest/nextmode) - Regex filtering for include / exclude
- Safe PEP 440 range resolution, maturity periods, and per-package policies
Installation
uv tool install taze
# or
uvx taze
# or
pip install taze
Usage
taze [mode] [options]
Modes
| Mode | What it shows |
|---|---|
default |
Latest stable release allowed by the declared PEP 440 range |
major |
Latest stable release, including major changes |
minor |
Latest stable release in the current major version |
patch |
Latest stable release in the current major/minor version |
latest |
Alias for major |
stable |
Range-safe stable updates |
newest |
All updates including pre-releases |
next |
Same as newest |
Examples
# Check everything in the current directory
taze
# Only show minor and patch updates
taze minor
# Write patch updates back to pyproject.toml
taze patch -w
# Write all updates and run uv sync
taze -w -i
# Interactive — pick which packages to update
taze -I
# Include pre-releases
taze newest
# Scan all subdirectories (monorepo)
taze -r
# Only check specific packages
taze -n requests,httpx
# Skip packages matching a pattern
taze -x /^pytest/
# Do not upgrade releases published in the last two weeks
taze --maturity-period 14
# Include exact == pins (they are skipped by default)
taze -l
# Sort by largest update first
taze --sort diff-desc
# Machine-readable JSON output
taze --json
Options
-w, --write Write updates back to file
-i, --install Install after writing (implies -w)
-u, --update Alias for --install
-I, --interactive Choose which packages to update interactively
-r, --recursive Scan subdirectories for pyproject.toml / requirements*.txt
--ignore-paths <glob> Comma-separated glob paths to skip with --recursive
--ignore-other-workspaces / --include-other-workspaces
Skip nested repositories and workspaces (default: skip)
-a, --all Show up-to-date packages too
-n, --include <deps> Only check these packages (comma-separated or /regex/)
-x, --exclude <deps> Skip these packages (comma-separated or /regex/)
-C, --cwd <path> Working directory
-s, --silent No output
-v, --version Show version
--sort <type> Sort output: name-asc | name-desc | diff-asc | diff-desc
--fail-on-outdated Exit with code 1 if any outdated dependencies are found
-l, --include-locked Include exact == version pins
--maturity-period <n>
Require a release to be at least n days old
--maturity-period-exclude <deps>
Bypass the maturity period for selected packages
--config <path> Read settings from a taze.toml file
--concurrency <n> Number of concurrent PyPI requests (default: 10)
--json Machine-readable JSON output
Output
📦 pyproject.toml /home/user/myproject/pyproject.toml
dependencies 3 outdated
packaging ~8mo >=25.2 → >=26.2 ~3mo MAJOR
rich ~4mo >=14.0.0 → >=15.0.0 ~3d MAJOR
typer ~6mo >=0.25.7 → >=0.26.7 ~3d minor
group:dev 1 outdated
ruff ~8mo >=0.14.1 → >=0.15.19 ~1d minor
Run taze -w to write 4 update(s) to pyproject.toml
The age columns show how old the current pinned version is and how recently the latest version was released — green for < 4 weeks, yellow for < 6 months, red for older.
Supported file formats
| File | Section |
|---|---|
pyproject.toml |
[project] dependencies |
pyproject.toml |
[project.optional-dependencies.*] |
pyproject.toml |
[dependency-groups.*] (PEP 735) |
pyproject.toml |
[tool.uv.dev-dependencies] |
pyproject.toml |
[tool.pdm.dev-dependencies.*] |
pyproject.toml |
[tool.hatch.envs.*.dependencies] |
requirements*.txt |
Standard pip format |
Monorepos
taze -r finds supported dependency files under the working directory. It skips
virtual environments, build/cache directories, and nested repositories/workspaces by
default. Use --ignore-paths examples/**,vendor/** for additional exclusions, or
--include-other-workspaces to deliberately scan nested workspaces.
Project names declared in workspace pyproject.toml files are recognised as local
packages and are not looked up on PyPI.
Configuration
Place options in taze.toml or in the [tool.taze] table of pyproject.toml.
CLI values take precedence over project configuration.
[tool.taze]
recursive = true
ignore-paths = ["examples/**", "vendor/**"]
maturity-period = 7
maturity-period-exclude = "internal-tools"
include-locked = false
[tool.taze.package-mode]
django = "minor"
"/pytest-.*/" = "patch"
setuptools = "ignore"
package-mode accepts every mode listed above, plus ignore. Exact package names
and slash-delimited regular expressions are supported.
Installation
taze -i writes updates, then chooses an installer from the project metadata:
uv sync, poetry install, pdm install, or pixi install. -u is an alias for
-i.
License
MIT
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file taze-0.2.1.tar.gz.
File metadata
- Download URL: taze-0.2.1.tar.gz
- Upload date:
- Size: 48.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4f6921a6ad008748f627794feb170ece51b385b1267f4719dfd133f34bf52e7c
|
|
| MD5 |
45a9612a592edb647573f7c593a99355
|
|
| BLAKE2b-256 |
90c9afcf0343b5d3d3cad4c778b480bd862d9d12064c8afbf6f3a27b2a1d8cfd
|
Provenance
The following attestation bundles were made for taze-0.2.1.tar.gz:
Publisher:
publish.yml on keksiqc/taze
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
taze-0.2.1.tar.gz -
Subject digest:
4f6921a6ad008748f627794feb170ece51b385b1267f4719dfd133f34bf52e7c - Sigstore transparency entry: 2137518044
- Sigstore integration time:
-
Permalink:
keksiqc/taze@77b1fc05188f8d1cd5b55f27087917dc97e0b676 -
Branch / Tag:
refs/tags/0.2.1 - Owner: https://github.com/keksiqc
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@77b1fc05188f8d1cd5b55f27087917dc97e0b676 -
Trigger Event:
release
-
Statement type:
File details
Details for the file taze-0.2.1-py3-none-any.whl.
File metadata
- Download URL: taze-0.2.1-py3-none-any.whl
- Upload date:
- Size: 21.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e6e1edf73c27fcee306e671f4dcf575f99195b8fd4eb7121be6285316ec4171b
|
|
| MD5 |
8a454cf6ca10a3e9be49424aa6a43603
|
|
| BLAKE2b-256 |
c0c8fa5f25e3c9bfa8ec72495126fadc117ff6bc3c9e2e1cc875b81e66ff7158
|
Provenance
The following attestation bundles were made for taze-0.2.1-py3-none-any.whl:
Publisher:
publish.yml on keksiqc/taze
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
taze-0.2.1-py3-none-any.whl -
Subject digest:
e6e1edf73c27fcee306e671f4dcf575f99195b8fd4eb7121be6285316ec4171b - Sigstore transparency entry: 2137518130
- Sigstore integration time:
-
Permalink:
keksiqc/taze@77b1fc05188f8d1cd5b55f27087917dc97e0b676 -
Branch / Tag:
refs/tags/0.2.1 - Owner: https://github.com/keksiqc
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@77b1fc05188f8d1cd5b55f27087917dc97e0b676 -
Trigger Event:
release
-
Statement type: