← All recipes
Moderne licensed

Upgrade Python dependency version

Recipe IDorg.openrewrite.python.UpgradeDependencyVersionArtifactorg.openrewrite:rewrite-python

Upgrade the version constraint for a dependency. Supports pyproject.toml (with scope/group targeting), requirements.txt, and Pipfile. For pyproject.toml, uv.lock, poetry.lock, and pdm.lock are regenerated natively without executing the package manager. For Pipfile, Pipfile.lock is regenerated natively by consulting the project's package index over the network. Not safe to use as a precondition: invokes the package manager or the network and publishes per-project state shared with other dependency recipes.

Single recipeMSAL

Add to your build

Get a download tokenThis recipe is Moderne licensed, so the token must belong to a Moderne customer. It replaces YOUR_DOWNLOAD_TOKEN below.

~/.gradle/gradle.properties

codeGenomeUsername=you@example.com
codeGenomeToken=YOUR_DOWNLOAD_TOKEN

build.gradle.kts

plugins {
    id("org.openrewrite.rewrite") version("latest.release")
}

rewrite {
    activeRecipe("org.openrewrite.python.UpgradeDependencyVersion")
}

repositories {
    mavenCentral()
    maven {
        url = uri("https://artifacts.codegenomeproject.org/maven")
        credentials {
            username = providers.gradleProperty("codeGenomeUsername").get()
            password = providers.gradleProperty("codeGenomeToken").get()
        }
    }
}

dependencies {
    rewrite("org.openrewrite:rewrite-python:8.92.8")
}

Then run

./gradlew rewriteRun

This recipe has required options, which a build sets in a rewrite.yml recipe that you activate instead.

Usage

You’ll need the Moderne CLI configured before running the command below.

mod run . --recipe org.openrewrite.python.UpgradeDependencyVersion --recipe-option "packageName=requests" --recipe-option "newVersion=>=2.31.0"

If the recipe isn’t available locally, install it with:

mod config recipes jar install org.openrewrite:rewrite-python:RELEASE

Options

NameTypeDescription
packageNamerequiredStringThe PyPI package name to update.
e.g. requests
newVersionrequiredStringThe new PEP 508 version constraint (e.g., >=2.31.0).
e.g. >=2.31.0
scopeStringThe dependency scope to update in. All scopes are searched by default.
e.g. project.dependencies
groupNameStringThe group name, required when scope is project.optional-dependencies or dependency-groups.
e.g. dev

Data tables

Structured output this recipe can produce.

  • Python lock regeneration failuresLock files that could not be regenerated after a dependency edit, and why.org.openrewrite.python.table.PythonLockRegenerationFailures
  • Source files that had resultsSource files that were modified by the recipe run.org.openrewrite.table.SourcesFileResults
  • Source files that had search resultsSearch results that were found during the recipe run.org.openrewrite.table.SearchResults
  • Source files that errored on a recipeThe details of all errors produced by a recipe run.org.openrewrite.table.SourcesFileErrors
  • Recipe performanceStatistics used in analyzing the performance of recipes.org.openrewrite.table.RecipeRunStats