Skip to main content

upd logo

upd

crates.io PyPI CI License: MIT

A fast dependency updater for Python, Node.js, Rust, Go, Ruby, .NET, Terraform, GitHub Actions, pre-commit, and Mise projects, written in Rust.

Quick Start

# Preview changes without modifying files (default)
uvx --from upd-cli upd

# Apply updates
uvx --from upd-cli upd --apply

# Or with pipx
pipx run --spec upd-cli upd --apply

Features

  • Multi-ecosystem: Python, Node.js, Rust, Go, Ruby, .NET, Terraform, GitHub Actions, pre-commit, Mise/asdf
  • Dry-run by default: nothing is written without --apply
  • Fast: parallel registry requests, with a 24-hour version cache
  • Constraint-aware: respects >=2.0,<3 (Python), ~> 7.1 (Ruby), and ^2.0.0 / ~2.0.0 (npm, Cargo)
  • Format-preserving: keeps formatting, comments, and structure
  • Update filters: --only-bump, --max-bump, --package, --lang, or approve one by one with -i
  • Major warnings: breaking changes are flagged with (MAJOR)
  • Pre-release aware: updates pre-releases to newer pre-releases
  • Cooldown: hold back releases younger than N days, against supply-chain attacks
  • Security auditing: OSV vulnerability scanning with auto-fix and SARIF output
  • Check mode: exit 1 if updates are available (for CI and pre-commit)
  • Gitignore-aware: honors .gitignore and prunes hidden directories, without missing the dotfiles it updates
  • Private registries: authentication for PyPI, npm, Cargo, Go, and GitHub
  • Config file: ignore or pin packages via .updrc.toml

Installation

From crates.io

cargo install upd

# or with cargo-binstall (faster, pre-built binary)
cargo binstall upd

From PyPI

pip install upd-cli
# or with uv
uv pip install upd-cli

From source

git clone https://github.com/rvben/upd
cd upd
cargo install --path .

Usage

# Preview changes without modifying files (default when no --apply)
upd

# Apply updates to files
upd --apply

# Limit to specific files or directories
upd --apply requirements.txt pyproject.toml

# Approve updates one by one
upd -i

# Only the packages you name
upd --package requests,flask

# Cap the bump level (allow patch + minor, skip major). Updates above the
# ceiling are reported as held back, never as up to date, and do not
# change the exit code.
upd --max-bump minor

# Restrict to exactly one level (repeatable, comma-separated)
upd --only-bump major

# One ecosystem at a time: python, node, rust, go, ruby, dot-net,
# terraform, actions, pre-commit, mise, annotated
upd --lang python

# Exit 1 if anything is outdated (for CI and pre-commit)
upd --check

# Regenerate lockfiles after writing
upd --apply --lock

# Print the effective configuration and exit
upd --show-config

upd --help lists every flag; Stability documents the ones that are contractual, and upd schema emits the whole interface as JSON.

Dry-run by default: upd without --apply only previews changes. Pass --apply to write updates. --check, --dry-run, and --interactive do not require --apply.

VCS-root scoping: When no path argument is given, upd scans from the nearest .git ancestor directory rather than the current working directory. This prevents accidental rewrites when CWD is a subdirectory inside a repository.

Commands

upd --version      # Print version
upd self-update    # Check for upd updates
upd clean-cache    # Clear the version cache
upd align          # Align versions across files (--check exits 1 on misalignment)
upd audit          # Scan for known vulnerabilities (exit 6 if found)
upd schema         # Machine-readable interface description

Example Output

.pre-commit-config.yaml:37: Would update pre-commit/pre-commit-hooks v4.6.0 → v6.0.0 (MAJOR)
.github/workflows/ci.yml:16: Would update actions/checkout v4 → v6 (MAJOR)
.github/workflows/ci.yml:18: Would update jdx/mise-action v2 → v4 (MAJOR)
.mise.toml:8: Would update rust 1.91.1 → 1.94.0
Cargo.toml:33: Would update clap 4.5.53 → 4.6.0
Cargo.toml:36: Would update tokio 1.48.0 → 1.50.0

Would update 6 package(s) (2 major, 3 minor, 1 patch) in 4 file(s), 8 up to date

Output includes clickable file:line: locations (recognized by VS Code, iTerm2, and modern terminals).

Version Constraints

upd respects version constraints in your dependency files:

Constraint Behavior
>=2.0,<3 Updates within 2.x range only
^2.0.0 Updates within 2.x range (npm/Cargo); never crosses the major bound
~2.0.0 Updates within 2.0.x range (npm); ~2.0.0 (Cargo) stays within 2.0.x
~> 7.1 Updates within 7.x range (Ruby pessimistic)
>=2.0 Updates to any version >= 2.0
==2.0.0 Updates the exact pin to the latest version (e.g. ==2.0.0==3.1.5). To freeze a package, use [pin] or ignore in .updrc.toml.

For npm, comparator ranges such as ">=1.0.0 <2.0.0" are rewritten with a bump strategy: the lower bound moves to the highest version satisfying the constraint, preserving the upper bound. Hyphen ("1 - 2") and OR ("^1 || ^2") ranges are reported as warnings and left untouched rather than rewritten wrongly.

Version Precision

By default, upd preserves version precision from the original file:

# Original file has 2-component versions
flask>=2.0        →  flask>=3.1        (not 3.1.5)
django>=4         →  django>=6         (not 6.0.0)

# Original file has 3-component versions
requests>=2.0.0   →  requests>=2.32.5

# GitHub Actions major-only tags
actions/checkout@v3  →  actions/checkout@v4  (not @v4.2.0)

Use --full-precision to always output full semver versions:

upd --full-precision
flask>=2.0        →  flask>=3.1.5
django>=4         →  django>=6.0.0
requests>=2.0.0   →  requests>=2.32.5

Version Alignment

In monorepos or projects with multiple dependency files, the same package might have different versions:

# requirements.txt
requests==2.28.0

# requirements-dev.txt
requests==2.31.0

# services/api/requirements.txt
requests==2.25.0

upd align updates every occurrence to the highest version found:

upd align              # Align all packages to highest version
upd align --dry-run    # Preview changes
upd align --check      # Exit 1 if misalignments (for CI)
upd align --lang python # Align only Python packages

It only aligns within one ecosystem, skips packages with upper bound constraints (e.g. >=2.0,<3.0) to avoid breaking them, and ignores pre-release versions when finding the highest version.

Pre-commit Integration

Add upd to your .pre-commit-config.yaml:

repos:
  - repo: https://github.com/rvben/upd-pre-commit
    rev: v0.0.24
    hooks:
      - id: upd-check
        # Optional: only check specific ecosystems
        # args: ['--lang', 'python']

Available hooks:

Hook ID Description
upd-check Fail if any dependencies are outdated
upd-check-major Fail only on major (breaking) updates

Both hooks run on pre-push by default. Uses language: python which installs upd-cli from PyPI automatically, so no manual installation is needed.

Documentation

Everything you look up rather than read lives in docs/.

Supported files

Every file upd discovers, per ecosystem, plus annotated version pins in files it does not otherwise understand. → docs/ecosystems.md

Security auditing

OSV vulnerability scanning, --fix-audit, SARIF output, and CI integration. → docs/audit.md

Configuration file

.updrc.toml discovery order and every key it accepts. → docs/configuration.md

Cooldown (minimum release age)

Hold back versions published less than N days ago, per ecosystem. → docs/configuration.md#cooldown-minimum-release-age

Caching

Where the 24-hour version cache lives and how to clear or bypass it. → docs/configuration.md#caching

Environment variables

Every variable upd reads, in one table. → docs/configuration.md#environment-variables

Private repositories

Credential detection for PyPI, npm, Cargo, Go, and GitHub, including private indexes declared in pyproject.toml. → docs/private-registries.md

GitHub Actions

SHA-pin safety rules, blocked vs not-examined reporting, and the reusable workflow that opens dependency pull requests. → docs/github-actions.md

Stability

The stable CLI surface, exit codes, --lock commands, and output guarantees. → docs/stability.md

Development

# Build
make build

# Run tests
make test

# Lint
make lint

# Format
make fmt

# All checks
make check

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

upd_cli-0.6.3.tar.gz (562.9 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

upd_cli-0.6.3-py3-none-win_amd64.whl (3.5 MB view details)

Uploaded Python 3Windows x86-64

upd_cli-0.6.3-py3-none-musllinux_1_2_x86_64.whl (5.4 MB view details)

Uploaded Python 3musllinux: musl 1.2+ x86-64

upd_cli-0.6.3-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (5.5 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

upd_cli-0.6.3-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (5.6 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

upd_cli-0.6.3-py3-none-macosx_11_0_arm64.whl (3.1 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

upd_cli-0.6.3-py3-none-macosx_10_12_x86_64.whl (3.3 MB view details)

Uploaded Python 3macOS 10.12+ x86-64

File details

Details for the file upd_cli-0.6.3.tar.gz.

File metadata

  • Download URL: upd_cli-0.6.3.tar.gz
  • Upload date:
  • Size: 562.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.7

File hashes

Hashes for upd_cli-0.6.3.tar.gz
Algorithm Hash digest
SHA256 1441a48f64e80d9cc952752361b2a16aafc13d02fae039d69e962a9c55c3daae
MD5 b2f8dde1d717be6343ef564bb1db934e
BLAKE2b-256 c761a45685cb6c73ed96173d91683f98becb6b7a4f35a332145f39675c4a2f6a

See more details on using hashes here.

File details

Details for the file upd_cli-0.6.3-py3-none-win_amd64.whl.

File metadata

  • Download URL: upd_cli-0.6.3-py3-none-win_amd64.whl
  • Upload date:
  • Size: 3.5 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.7

File hashes

Hashes for upd_cli-0.6.3-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 559970c33974a82a164a8907bbf505153a25cde99f734df234434f225b84a96d
MD5 8dfd67164bef6977b2a0fa54324e1a44
BLAKE2b-256 dd39c7c2047765c5dd62e5fa3a05e8131402680c84c074bd5c18e756cc7973d2

See more details on using hashes here.

File details

Details for the file upd_cli-0.6.3-py3-none-musllinux_1_2_x86_64.whl.

File metadata

File hashes

Hashes for upd_cli-0.6.3-py3-none-musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 5f5530a8ce3d2e380fb02f1ee0fd00bfaa7f32c3d6f7013b1620c704e951e788
MD5 401ea8d07d28b61ebccc10d50fe3b189
BLAKE2b-256 2c4c5c0c1f2705687c4bfb30d2a6b178813bc63cb792211ec97f254232025af8

See more details on using hashes here.

File details

Details for the file upd_cli-0.6.3-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for upd_cli-0.6.3-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 b393113e8807a7716b94494e8c029c4b18c95bc237ef2455390b532b44e16e89
MD5 d20dd615b284a440a84d3d2be9a70254
BLAKE2b-256 7a8c5dd9b97084b92ba3fdbff391a1116a8bf1996e5c26721342619e406804de

See more details on using hashes here.

File details

Details for the file upd_cli-0.6.3-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for upd_cli-0.6.3-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 b5175799be3c21441267ec7e7a0a705ab9c5df2e3842c1266e73918aab68a0f4
MD5 e2481bc1fcb2af759494009c52e5da32
BLAKE2b-256 185d5965da4b28a9a7cdf8f01dc8a71af6d227f236c6135f692ae40e1a0a2776

See more details on using hashes here.

File details

Details for the file upd_cli-0.6.3-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for upd_cli-0.6.3-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 60e73eb001c24dc641403e312a9f2f3a6a5e66bbdbc1017d805a5c41fe36865c
MD5 5da478eec33c22577b73fd23f764032f
BLAKE2b-256 1a8f3fffbbc6798479f16363b154f6d7d9ffb91751bb8600340fa22c05e080a2

See more details on using hashes here.

File details

Details for the file upd_cli-0.6.3-py3-none-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for upd_cli-0.6.3-py3-none-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 4573a2caa8ba01f5352089383b59b62ed9084a11ee17c6ade2c012b305230b70
MD5 8d5c32c56c8d75787973f8c1d6decf1c
BLAKE2b-256 5086861b2f2c4b17bfff708db649c4cd085ceef3887cbe10e6dd6980d6ad2e38

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.6.3 This release

7 files

0.6.2

7 files

0.6.1

7 files

0.6.0

7 files

0.5.4

7 files

0.5.3

7 files

0.5.2

7 files

0.5.1

7 files

0.5.0

7 files

0.4.1

7 files

0.4.0

7 files

0.3.1

7 files

0.3.0

7 files

0.2.4

7 files

0.2.3

7 files

0.2.2

7 files

0.2.1

7 files

0.2.0

7 files

0.1.10

7 files

0.1.9

7 files

0.1.8

7 files

0.1.7

7 files

0.1.6

7 files

0.1.5

7 files

0.1.4

7 files

0.1.3

7 files

0.1.2

7 files

0.1.1

7 files

0.0.28

7 files

0.0.27

7 files

0.0.26

7 files

0.0.25

7 files

0.0.24

7 files

0.0.23

7 files

0.0.22

7 files

0.0.21

7 files

0.0.20

7 files

0.0.19

7 files

0.0.18

7 files

0.0.17

7 files

0.0.16

7 files

0.0.15

7 files

0.0.14

7 files

0.0.13

7 files

0.0.12

7 files

0.0.11

7 files

0.0.10

7 files

0.0.9

7 files

0.0.8

7 files

0.0.7

7 files

0.0.6

7 files

0.0.5

7 files

0.0.4

7 files

0.0.3

7 files

0.0.2

7 files

0.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page