PyPI
| source | condition | target |
|---|---|---|
✔ | ✔ | ✗ |
Description
The pypi resource queries a PyPI-compatible registry for the versions of a Python package.
- source
Returns the version matching
versionfilter.- condition
Checks that
versionexists on the registry.- target
Not supported - a target fails with
target not supported for the pypi plugin. To bump a pinned version in a file, use the "File" resource or the pyproject autodiscovery crawler.
Note | An scm attached to a condition is ignored, with a warning (the lookup always goes to the registry). |
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| name | string | “name” defines the PyPI package name. compatible:
remark:
example:
| |
| token | string | “token” defines the bearer token used to authenticate with a private registry. compatible:
| |
| url | string | “url” defines the url of a PyPI compatible registry. compatible:
default: https://pypi.org/ | |
| version | string | “version” defines the package version to check. compatible:
default: the output of the associated source. | |
| versionfilter | object | “versionfilter” defines the version pattern and its kind, such as “pep440”, “semver” or “latest”. compatible:
default: latest remark:
| |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
|
nameThe project name as published, e.g.
requests.urlDefaults to
https://pypi.org/. Point it at a private index that speaks the same JSON API.tokenBearer token for a private registry. Keep it out of the manifest with
'{{ requiredEnv "PYPI_TOKEN" }}'.versionCondition only - the version whose existence is being checked.
Versions, PEP 440 and yanked releases
Yanked releases are always excluded, whatever the filter. A version withdrawn by its maintainer is never returned by a source, matching what pip does by default.
PEP 440 and semver disagree about how a pre-release is written (1.2.3rc1 against 1.2.3-rc1), so the resource handles them differently depending on the filter:
kind: pep440Versions are compared as raw PEP 440 strings, untouched.
- any other kind
Versions are normalised to a semver-compatible form for matching, then the original PEP 440 string is returned. So a
semverfilter can match1.2.3-rc1internally while the source still yields1.2.3rc1, which is what a requirements file needs.
A version that cannot be normalised is skipped rather than failing the run. See the "Version Filtering" page.
Example
# updatecli.yaml
name: PyPI resource example
sources:
requests:
name: Get latest requests version from PyPI
kind: pypi
spec:
name: requests
flask:
name: Get latest flask version matching >=3.0
kind: pypi
spec:
name: flask
versionfilter:
kind: semver
pattern: ">=3.0.0"
conditions:
requests:
name: Test that requests version 2.31.0 exists on PyPI
kind: pypi
disablesourceinput: true
spec:
name: requests
version: 2.31.0
targets:
# Targets are not supported