New — updates now run inside the interface

One command.
153 sources
up to date.

Stop chasing winget, brew and npm, pip, cargo and helm. gup scans them all in parallel, shows what is outdated and updates what you pick — live, in a terminal embedded in its interface.

npm install -g @charles_lindecker/gup --allow-scripts=node-pty

View on GitHub
  • MIT · open source
  • Node ≥ 26
  • Windows · macOS · Linux
  • Zero telemetry
  • 0 daemon · opt-in scheduling
gup in action

gup v0.5.147 detected5 updatesnormal mode

Menu

  • Scan
  • Packages5
  • Schedules1
  • Providers
  • Journal
  • Options
  • Quit

Packages

SelectionPackageCurrentLatest
partly checkedHomebrew2/3
checkedripgrep14.1.0→ 14.1.1
checkedfzf0.54.0→ 0.55.0
not checkedscheduledbat0.24.0→ 0.25.0
partly checkednpm (global)1/2
checkedtypescript5.5.4→ 5.6.2
not checkedpnpm9.6.0→ 9.12.1

● 3 of 5 checkedEnter Update (3)

space check · / filter · p schedule · a check all · ↑↓ navigate · r rescan · enter update (3) · tab menu · q quit

The interface is in English by default and in French with gup language fr. Commands, flags and JSON output are the same in every language.

01 / FEATURES

Everything happens in one interface.

Scan, choose, update, schedule and review — gup keeps you in a single full-screen terminal app.

  • New

    Updates without leaving gup

    Installers run in a terminal pane embedded in the interface — progress bars, prompts and colors intact. Updated packages then leave the list, no rescan needed. If the embedded terminal is unavailable, gup says why and updates in your own terminal instead.

  • Pick several, launch once

    Check packages with Space, select everything with a, launch with Enter. One queue, one summary.

  • New

    Scheduled updates, package by package

    Check packages and press p: ripgrep goes on a weekly schedule, node stays put. Schedules name packages, never a whole provider; your OS scheduler starts gup briefly to run what is due, so nothing stays resident.

  • Activity journal

    Every scan and update is logged locally. Terminal charts show your activity and which packages update most often; export the log to debug.

  • New

    HTML report

    gup report, or o in the journal, opens a clear, navigable report of your history in the browser — a single offline file, readable by anyone, not just terminal users.

  • Themes that stay readable

    Ten built-in themes or your own colors: gup checks each one against WCAG AA — 4.5:1 for text, 3:1 for borders, 7:1 if you pick AAA — and corrects what falls short.

  • Aware of your OS

    Providers that cannot run on your system are greyed out, not hidden: Windows-only tools show as such on a Mac, and the other way round.

  • Built for scripts and CI

    gup list --json, stable exit codes, -y to skip prompts, and provider:package targets that bypass the scan.

02 / COVERAGE

153 sources. Three systems. One binary.

The same executable on Windows, macOS and Linux — same provider contract, same JSON. What changes is the OS layer gup can drive.

  • Primary target

    Windows

    Supported providers
    139 / 153
    • winget
    • scoop
    • chocolatey
    • WSL

    WSL bridge: apt, dnf, pacman, Flatpak, Nix and Linuxbrew inside your distros.

  • Native

    macOS

    Supported providers
    132 / 153
    • Homebrew
    • Homebrew Casks
    • MacPorts
    • Mac App Store

    Apple Silicon and Intel · brew Cellar symlinks resolved · mas optional.

  • Native

    Linux

    Supported providers
    126 / 153
    • Homebrew / Linuxbrew
    • Nix
    • apt · delegation
    • dnf · delegation

    A binary's owner is resolved with dpkg -S or rpm -qf, then the update goes back to that manager.

Same everywhere

  • npm
  • pnpm
  • yarn
  • bun
  • pip
  • pipx
  • uv
  • cargo
  • rustup
  • gem
  • composer
  • dotnet tools
  • helm
  • kubectl
  • terraform
  • VS Code
  • JetBrains
  • gh extensions
  • pwsh modules
  • asdf
  • mise
All 153 providers, by domain
OS package managers
brew · brew-cask · choco · cygwin · fink · macports · mas · msys2 · nix · npackd · pkgin · pkgx · scoop · sparkle · winget
WSL
wsl · wsl-apt · wsl-brew · wsl-dnf · wsl-flatpak · wsl-nix · wsl-pacman
Node.js
bun-g · corepack · deno · fnm · npm-g · nvm · nvm-windows · pnpm-g · volta · yarn-g
Python
conda · pdm · pip · pipx · poetry · pyenv · pyenv-win · rye · uv-tools
.NET and PHP
composer-g · composer-self · dotnet-sdk · dotnet-tools · nuget · phive · symfony-cli
JVM
coursier-cs · jbang
Rust
cargo · rustup
Other languages
R-packages · cabal · flutter · gem · hex · julia-pkg · luarocks · mint · mix-archive · nimble · opam · pub-global · stack · vcpkg
Version managers
asdf · goenv · mise · proto · sdkman · swiftly
Cloud CLIs
aws-cli-v2 · az · doctl · flyctl · gcloud · hcloud · heroku · linode-cli · oci-cli · railway · scw · supabase
Infrastructure as code
boundary · consul · nomad · opentofu · packer · pulumi · terraform · terragrunt · tflint · vault
Kubernetes
argocd · flux · helm · helm-plugins · helm-repo · k3d · kind · krew · kubectl · kustomize · minikube · skaffold · tilt
Containers
dive · docker-desktop · nerdctl · oras · podman-desktop · rancher-desktop
Security tooling
cosign · gitsign · grype · nuclei · nuclei-templates · pdtm · rekor · semgrep · syft · trivy
Developer CLIs
delta · gh-ext · git-for-windows · glab · jj · lazydocker · lazygit · tea
IDEs and editors
cursor-ext · jetbrains · visual-studio · vscode-ext · vscodium-ext · windsurf-ext
Editor plugins
nvim-lazy · nvim-mason · nvim-packer · vim-plug
Embedded and mobile
android-sdk · arduino-cli · expo · fastlane · platformio · xcodes
Shell and prompt
nerd-fonts · oh-my-posh · psresource · pwsh-modules · starship
gup itself
self
Browse the full provider catalog

03 / HOW IT WORKS

An orchestrator, not another package manager.

gup runs each tool's own commands in parallel and lines the answers up. No registry, no cache, nothing left running.

  1. Scan

    Every detected provider answers listOutdated(), four at a time. One that fails only affects its own row.

  2. Choose

    Review packages grouped by provider, filter, select — or skip the scan with gup update brew:fzf.

  3. Update

    Native commands run as an argument vector, never through a shell. Every attempt lands in the local journal.

Architecture in detail

04 / SECURITY

It runs privileged commands. It is built accordingly.

One shell-out point, strict argument vectors, an allowlist pinned by tests — and every commit goes through three static analyzers.

  • Execution

    Subprocesses run as strict argv vectors, never shell: true, through a single audited entry point.

    • execa
    • argv
    • no shell
  • Supply chain

    HTTPS-only fetches, dependencies audited on every build, updates reviewed weekly.

    • audit-ci
    • Dependabot
    • gitleaks
  • Static analysis

    CodeQL, Semgrep and eslint-plugin-security on every commit, plus a test suite dedicated to security invariants.

    • CodeQL
    • Semgrep
    • eslint-security

05 / FAQ

Questions, answered.

Does gup replace winget, brew or npm?

No. gup orchestrates each tool's native commands (winget upgrade, brew outdated, npm update -g, pip list --outdated…) behind one interface. No invented protocol, no version cache.

Does it work on macOS and Linux?

Yes. On macOS natively: Homebrew formulae and casks, MacPorts and the Mac App Store, on Apple Silicon and Intel. On Linux, Homebrew/Linuxbrew and Nix cover the OS level, and a binary installed by the distribution is handed back to apt or dnf. Everything above the OS layer — npm, pip, cargo, helm, VS Code… — behaves the same on all three systems.

How do I install gup?

npm install -g @charles_lindecker/gup --allow-scripts=node-pty, then gup doctor to see which providers are detected. Requires Node.js 26.9.0 or later. --allow-scripts=node-pty approves the install scripts of node-pty, which powers the embedded terminal: without it, npm 11 warns and npm 12 skips them.

Can I use gup in CI?

Yes. gup list --json --fast gives machine-readable output and gup update --all -y skips every prompt. Exit codes are stable: 0 success, 1 partial failure, 2 invalid arguments.

How many package managers does gup cover?

153 providers, one isolated module each: winget, scoop, chocolatey, Homebrew, MacPorts, npm, pnpm, pip, uv, cargo, gem, composer, dotnet tools, helm, kubectl, terraform, VS Code extensions, JetBrains IDEs, WSL distributions and more.

Is it safe to run?

Every subprocess goes through one entry point as a strict argument vector — never through a shell — with an allowlist pinned by tests. CodeQL, Semgrep, gitleaks, audit-ci and Dependabot run continuously. gup sends no telemetry.

How is it different from topgrade?

topgrade runs updates; gup first answers “what is outdated, from which version to which”. The scan is a separate step with JSON output, package-by-package selection, provider:package targets, per-package schedules and a local history you can review.

Which language is the interface in?

English by default. gup language fr switches it to French and saves the choice; GUP_LANG=fr does the same for a single shell and takes precedence over it. Commands, flags and JSON output are language-neutral, and this site is available in eight languages.

06 / INSTALL

Thirty seconds, and you know everything.

One npm install, one command, and the full list of what is outdated on your machine.

npm install -g @charles_lindecker/gup --allow-scripts=node-pty

  • gupFull-screen interface
  • gup list --fastWhat is outdated, fast scan
  • gup update --all -yEverything, no prompt (CI)
  • gup update brew:fzfOne package, no scan
  • gup doctorWhat is detected, and how to install the rest