Description

The pyproject crawler looks recursively for all Python dependencies from pyproject.toml files. It detects the package manager in use via lock files (currently uv.lock is supported) and generates manifests to update dependencies using the appropriate tool.

Dependencies are discovered from both [project.dependencies] and [project.optional-dependencies] sections. PEP 508 dependency strings are parsed to extract package names and version constraints. Environment markers are stripped.

Generated manifests use the pypi resource as a source and uv add as a shell target, which atomically updates both pyproject.toml and uv.lock.

Manifest

Parameters

NameTypeDescriptionRequired
ignorearrayIgnore specifies rules to exclude pyproject.toml dependencies from autodiscovery.
    packagesobjectPackages specifies the list of Python packages to match, keyed by package name. The value is a PEP 440 version specifier (e.g. “>=2.0,<3.0”) or empty to match any version.
    pathstringPath specifies a pyproject.toml path pattern. The pattern must match the full path, not just a substring. Wildcards accepted by filepath.Match are supported.
indexurlstringIndexURL specifies a custom PyPI index URL propagated to all generated source specs. It carries no credentials: authenticating against a private registry requires setting the pypi resource token field on the generated manifests.
onlyarrayOnly specifies rules to restrict autodiscovery to matching pyproject.toml dependencies.
    packagesobjectPackages specifies the list of Python packages to match, keyed by package name. The value is a PEP 440 version specifier (e.g. “>=2.0,<3.0”) or empty to match any version.
    pathstringPath specifies a pyproject.toml path pattern. The pattern must match the full path, not just a substring. Wildcards accepted by filepath.Match are supported.
rootdirstringRootDir defines the root directory used to recursively search for pyproject.toml files.
versionfilterobject

versionfilter provides parameters to specify the version pattern used when generating manifest.

If unspecified, Updatecli falls back to kind pep440 and reuses each dependency’s own constraint as the pattern, such as >=2.28 for requests>=2.28, or * when the dependency is declared without a constraint.

kind - pep440 (default) versionfilter of kind pep440 uses PEP 440 version specifiers natively pattern accepts a PEP 440 version specifier such as >=2.28, >=1.0,<3.0, or * (any)

kind - semver versionfilter of kind semver uses semantic versioning as version filtering pattern accepts one of: prerelease - Updatecli tries to identify the latest prerelease whatever it means patch - Updatecli only handles patch version update minor - Updatecli handles patch AND minor version update minoronly - Updatecli handles minor version only major - Updatecli handles patch, minor, AND major version update majoronly - Updatecli only handles major version update a version constraint such as >= 1.0.0 relative patterns such as minor are resolved against the version currently declared by each dependency, so minor generates the pattern 2.x for requests>=2.28

kind - regex versionfilter of kind regex uses regular expression as version filtering pattern accepts a valid regular expression

example:

  versionfilter:
    kind: pep440
    pattern: ">=2.28"

More examples can be found at https://www.updatecli.io/docs/core/versionfilter/

    kindstringspecifies the version kind such as semver, regex, or latest
    patternstringspecifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format
    regexstringspecifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used.
    replaceallobjectreplaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction.
        patternstringPattern specifies the regex pattern to match for replacement
        replacementstringReplacement specifies the replacement string (supports $1, $2, etc. for captured groups)
    strictbooleanstrict enforce strict versioning rule. Only used for semantic versioning at this time
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli

Example

Basic Example
# updatecli.d/pyproject.yaml
autodiscovery:
  crawlers:
    pyproject:
      rootdir: "."
      versionfilter:
        kind: semver
        pattern: minor
Filter to Specific Packages
# updatecli.d/pyproject-only.yaml
autodiscovery:
  crawlers:
    pyproject:
      only:
        - packages:
            "requests": ""
            "flask": ""
Private PyPI Registry
# updatecli.d/pyproject-private.yaml
autodiscovery:
  crawlers:
    pyproject:
      rootdir: "."
      # Custom PyPI index URL propagated to all generated pypi source specs
      indexurl: "https://pypi.example.com/"
      versionfilter:
        kind: semver
        pattern: ">=1.0.0"
Note
The indexurl parameter is propagated to all generated pypi resource specs, allowing consistent registry configuration across all discovered dependencies. For private registry authentication, the pypi resource supports a token field for Bearer token auth.
Note
The alias python/uv can also be used instead of pyproject.