Pyproject
kind: pyproject
Description
The pyproject crawler looks recursively for all Python dependencies from pyproject.toml files.
It detects the package manager in use via lock files (currently uv.lock is supported) and generates manifests to update dependencies using the appropriate tool.
Dependencies are discovered from both [project.dependencies] and [project.optional-dependencies] sections. PEP 508 dependency strings are parsed to extract package names and version constraints. Environment markers are stripped.
Generated manifests use the pypi resource as a source and uv add as a shell target, which atomically updates both pyproject.toml and uv.lock.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| ignore | array | Ignore specifies rules to exclude pyproject.toml dependencies from autodiscovery. | |
| packages | object | Packages specifies the list of Python packages to match, keyed by package name. The value is a PEP 440 version specifier (e.g. “>=2.0,<3.0”) or empty to match any version. | |
| path | string | Path specifies a pyproject.toml path pattern. The pattern must match the full path, not just a substring. Wildcards accepted by filepath.Match are supported. | |
| indexurl | string | IndexURL specifies a custom PyPI index URL propagated to all generated source specs. | |
| only | array | Only specifies rules to restrict autodiscovery to matching pyproject.toml dependencies. | |
| packages | object | Packages specifies the list of Python packages to match, keyed by package name. The value is a PEP 440 version specifier (e.g. “>=2.0,<3.0”) or empty to match any version. | |
| path | string | Path specifies a pyproject.toml path pattern. The pattern must match the full path, not just a substring. Wildcards accepted by filepath.Match are supported. | |
| rootdir | string | RootDir defines the root directory used to recursively search for pyproject.toml files. | |
| versionfilter | object |
kind - semver
versionfilter of kind kind - regex
versionfilter of kind example:
and its type like regex, semver, or just latest. More examples can be found at https://www.updatecli.io/docs/core/versionfilter/ |
|
| kind | string | specifies the version kind such as semver, regex, or latest | |
| pattern | string | specifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format | |
| regex | string | specifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used. | |
| replaceall | object | replaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction. | |
| pattern | string | Pattern specifies the regex pattern to match for replacement | |
| replacement | string | Replacement specifies the replacement string (supports $1, $2, etc. for captured groups) | |
| strict | boolean | strict enforce strict versioning rule. Only used for semantic versioning at this time |
Example
Basic Example
# updatecli.d/pyproject.yaml
autodiscovery:
crawlers:
pyproject:
rootdir: "."
versionfilter:
kind: semver
pattern: minor
Filter to Specific Packages
# updatecli.d/pyproject-only.yaml
autodiscovery:
crawlers:
pyproject:
only:
- packages:
"requests": ""
"flask": ""
Private PyPI Registry
# updatecli.d/pyproject-private.yaml
autodiscovery:
crawlers:
pyproject:
rootdir: "."
# Custom PyPI index URL propagated to all generated pypi source specs
indexurl: "https://pypi.example.com/"
versionfilter:
kind: semver
pattern: ">=1.0.0"
|
Note
|
The indexurl parameter is propagated to all generated pypi resource specs, allowing consistent registry configuration across all discovered dependencies. For private registry authentication, the pypi resource supports a token field for Bearer token auth.
|
|
Note
|
The alias python/uv can also be used instead of pyproject.
|