Skip to main content

CLI to audit uv-managed dependency pins across a workspace

Project description

uvbump (distribution: uvbump-cli)

CLI helper that inspects a uv-managed project (or workspace) and reports which dependencies can be bumped based on what is pinned in pyproject.toml, what is installed in your lockfile environment, and what is currently available on PyPI.

Quick start

  1. Install uv: https://docs.astral.sh/uv/.
  2. Install uvbump once published: pip install uvbump-cli (or uv tool install uvbump-cli).
  3. From a uv project root, run uvbump to print two tables:
    • Packages out of date: your pins lag behind the newest versions on PyPI.
    • Packages can be bumped: installed versions differ from the versions pinned in pyproject.toml.
$ uvbump --root .
Packages out of date:
Package Name                                      Installed Version             Project Version               Newest Version                Suggested Action
requests                                         2.32.3                       2.31.0                         2.32.3                        Update package version

Packages can be bumped:
Package Name                                      Installed Version             Project Version               Newest Version                Suggested Action
requests                                         2.32.3                       2.31.0                         2.32.3                        Bump package version in project specification

Usage

uvbump --root /path/to/project

Install and run as a uv tool

uv tool install uvbump-cli
uvbump --root /path/to/project

Examples:

# uv workspace (default)
uvbump --root .

# npm project
uvbump --kind npm --root path/to/frontend

# upgrade all dependencies (uv)
uvbump --root . --upgrade

# interactively choose upgrades (npm)
uvbump --kind npm --root path/to/frontend --upgrade --interactive --group-by package

# preview upgrade changes without writing files
uvbump --root . --upgrade --dry-run

Common flags:

  • --root (optional): path to the directory that contains pyproject.toml or package.json. Defaults to the current working directory.
  • --kind (optional): uv or npm (default: uv).
  • --timeout (optional): subprocess timeout in seconds for uv/uvx/npm calls.
  • --upgrade: rewrite dependency versions to the newest available versions.
  • --interactive: pick which dependencies to upgrade.
  • --group-by (interactive only): workspace or package (default: workspace).
  • --dry-run: preview upgrade changes without writing files.
  • --version: print the current uvbump version.

The command uses uv export and uvx pip index versions under the hood for uv projects, so make sure uv is on your PATH.

Development

  • Run locally with uv run python -m uvbump --root examples to exercise the sample workspace in examples/.
  • Formatting/linting is handled by ruff; run ruff check and ruff format as needed.

Docker test harness

  • Build an image that prepares custom mismatched environments: docker build -t uvbump-tests .
  • Version scenarios are driven by Jinja templates:
    • Edit examples/version.env for the pin you want in pyproject.toml.jinja files and the install versions you want in the environment.
    • On container start the entrypoint sources that env file, renders each *.jinja under examples/ into pyproject.toml, and installs the requested runtime packages.
  • Run a sample check: docker run --rm -e VERSION_ENV=/app/examples/version.env uvbump-tests python -m uvbump --root examples
  • Opt out of installs with SKIP_INSTALL=1, skip template rendering with SKIP_TEMPLATE_RENDER=1, or skip the whole version step with SKIP_VERSION_CONFIG=1.

Building & publishing to PyPI

  1. Build artifacts: uv build (uses Hatchling under the hood).
  2. Verify contents: inspect dist/ for the wheel and sdist.
  3. Publish (after configuring credentials): uv publish --token <pypi-token> or python -m twine upload dist/*.

The project metadata lives in pyproject.toml; update the version there before each release.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

uvbump_cli-1.4.0.tar.gz (12.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

uvbump_cli-1.4.0-py3-none-any.whl (12.1 kB view details)

Uploaded Python 3

File details

Details for the file uvbump_cli-1.4.0.tar.gz.

File metadata

  • Download URL: uvbump_cli-1.4.0.tar.gz
  • Upload date:
  • Size: 12.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.9.28 {"installer":{"name":"uv","version":"0.9.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for uvbump_cli-1.4.0.tar.gz
Algorithm Hash digest
SHA256 9b21e746fb1ca6558d69eb1a85adcbe95bd5ed3bd530c6c5c4217e2055b8ca85
MD5 9c0ada25168e6d59878171704b00fde4
BLAKE2b-256 43414e14af16a3c6803f3c995fd967ed6db0110cea765f2b47d403ce417f1d05

See more details on using hashes here.

File details

Details for the file uvbump_cli-1.4.0-py3-none-any.whl.

File metadata

  • Download URL: uvbump_cli-1.4.0-py3-none-any.whl
  • Upload date:
  • Size: 12.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.9.28 {"installer":{"name":"uv","version":"0.9.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for uvbump_cli-1.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 b1344cd6e2e0ae306fc21918cd17c6c4d773afe5cc6e7695cf1c06a0d540af3c
MD5 e155db537511e8eb4177bd979f8a35bc
BLAKE2b-256 afc8fd973a81cf3eb8ebc390c1ac469c5de520a181e8960e882421e293764b03

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page