New — updates now run inside the interface
One command.
153 sources
up to date.
Stop chasing winget, brew and npm, pip, cargo and helm. gup scans them all in parallel, shows what is outdated and updates what you pick — live, in a terminal embedded in its interface.
npm install -g @charles_lindecker/gup --allow-scripts=node-pty
- MIT · open source
- Node ≥ 26
- Windows · macOS · Linux
- Zero telemetry
- 0 daemon · opt-in scheduling
gup v0.5.147 detected5 updatesnormal mode
Menu
- Scan
- Packages5
- Schedules1
- Providers
- Journal
- Options
- Quit
Packages
| Selection | Package | Current | Latest |
|---|---|---|---|
| partly checked | Homebrew2/3 | ||
| checked | ripgrep | 14.1.0 | → 14.1.1 |
| checked | fzf | 0.54.0 | → 0.55.0 |
| not checkedscheduled | bat | 0.24.0 | → 0.25.0 |
| partly checked | npm (global)1/2 | ||
| checked | typescript | 5.5.4 | → 5.6.2 |
| not checked | pnpm | 9.6.0 | → 9.12.1 |
space check · / filter · p schedule · a check all · ↑↓ navigate · r rescan · enter update (3) · tab menu · q quit
gup language fr. Commands, flags and JSON output are the same in every language.01 / FEATURES
Everything happens in one interface.
Scan, choose, update, schedule and review — gup keeps you in a single full-screen terminal app.
New
Updates without leaving gup
Installers run in a terminal pane embedded in the interface — progress bars, prompts and colors intact. Updated packages then leave the list, no rescan needed. If the embedded terminal is unavailable, gup says why and updates in your own terminal instead.
Pick several, launch once
Check packages with Space, select everything with a, launch with Enter. One queue, one summary.
New
Scheduled updates, package by package
Check packages and press p:
ripgrepgoes on a weekly schedule,nodestays put. Schedules name packages, never a whole provider; your OS scheduler starts gup briefly to run what is due, so nothing stays resident.Activity journal
Every scan and update is logged locally. Terminal charts show your activity and which packages update most often; export the log to debug.
New
HTML report
gup report, or o in the journal, opens a clear, navigable report of your history in the browser — a single offline file, readable by anyone, not just terminal users.Themes that stay readable
Ten built-in themes or your own colors: gup checks each one against WCAG AA — 4.5:1 for text, 3:1 for borders, 7:1 if you pick AAA — and corrects what falls short.
Aware of your OS
Providers that cannot run on your system are greyed out, not hidden: Windows-only tools show as such on a Mac, and the other way round.
Built for scripts and CI
gup list --json, stable exit codes,-yto skip prompts, andprovider:packagetargets that bypass the scan.
02 / COVERAGE
153 sources. Three systems. One binary.
The same executable on Windows, macOS and Linux — same provider contract, same JSON. What changes is the OS layer gup can drive.
Primary target
Windows
- Supported providers
- 139 / 153
- winget
- scoop
- chocolatey
- WSL
WSL bridge: apt, dnf, pacman, Flatpak, Nix and Linuxbrew inside your distros.
Native
macOS
- Supported providers
- 132 / 153
- Homebrew
- Homebrew Casks
- MacPorts
- Mac App Store
Apple Silicon and Intel · brew Cellar symlinks resolved ·
masoptional.Native
Linux
- Supported providers
- 126 / 153
- Homebrew / Linuxbrew
- Nix
- apt · delegation
- dnf · delegation
A binary's owner is resolved with
dpkg -Sorrpm -qf, then the update goes back to that manager.
Same everywhere
- npm
- pnpm
- yarn
- bun
- pip
- pipx
- uv
- cargo
- rustup
- gem
- composer
- dotnet tools
- helm
- kubectl
- terraform
- VS Code
- JetBrains
- gh extensions
- pwsh modules
- asdf
- mise
All 153 providers, by domain
- OS package managers
- brew · brew-cask · choco · cygwin · fink · macports · mas · msys2 · nix · npackd · pkgin · pkgx · scoop · sparkle · winget
- WSL
- wsl · wsl-apt · wsl-brew · wsl-dnf · wsl-flatpak · wsl-nix · wsl-pacman
- Node.js
- bun-g · corepack · deno · fnm · npm-g · nvm · nvm-windows · pnpm-g · volta · yarn-g
- Python
- conda · pdm · pip · pipx · poetry · pyenv · pyenv-win · rye · uv-tools
- .NET and PHP
- composer-g · composer-self · dotnet-sdk · dotnet-tools · nuget · phive · symfony-cli
- JVM
- coursier-cs · jbang
- Rust
- cargo · rustup
- Other languages
- R-packages · cabal · flutter · gem · hex · julia-pkg · luarocks · mint · mix-archive · nimble · opam · pub-global · stack · vcpkg
- Version managers
- asdf · goenv · mise · proto · sdkman · swiftly
- Cloud CLIs
- aws-cli-v2 · az · doctl · flyctl · gcloud · hcloud · heroku · linode-cli · oci-cli · railway · scw · supabase
- Infrastructure as code
- boundary · consul · nomad · opentofu · packer · pulumi · terraform · terragrunt · tflint · vault
- Kubernetes
- argocd · flux · helm · helm-plugins · helm-repo · k3d · kind · krew · kubectl · kustomize · minikube · skaffold · tilt
- Containers
- dive · docker-desktop · nerdctl · oras · podman-desktop · rancher-desktop
- Security tooling
- cosign · gitsign · grype · nuclei · nuclei-templates · pdtm · rekor · semgrep · syft · trivy
- Developer CLIs
- delta · gh-ext · git-for-windows · glab · jj · lazydocker · lazygit · tea
- IDEs and editors
- cursor-ext · jetbrains · visual-studio · vscode-ext · vscodium-ext · windsurf-ext
- Editor plugins
- nvim-lazy · nvim-mason · nvim-packer · vim-plug
- Embedded and mobile
- android-sdk · arduino-cli · expo · fastlane · platformio · xcodes
- Shell and prompt
- nerd-fonts · oh-my-posh · psresource · pwsh-modules · starship
- gup itself
- self
03 / HOW IT WORKS
An orchestrator, not another package manager.
gup runs each tool's own commands in parallel and lines the answers up. No registry, no cache, nothing left running.
Scan
Every detected provider answers
listOutdated(), four at a time. One that fails only affects its own row.Choose
Review packages grouped by provider, filter, select — or skip the scan with
gup update brew:fzf.Update
Native commands run as an argument vector, never through a shell. Every attempt lands in the local journal.
04 / SECURITY
It runs privileged commands. It is built accordingly.
One shell-out point, strict argument vectors, an allowlist pinned by tests — and every commit goes through three static analyzers.
Execution
Subprocesses run as strict argv vectors, never
shell: true, through a single audited entry point.Supply chain
HTTPS-only fetches, dependencies audited on every build, updates reviewed weekly.
Static analysis
CodeQL, Semgrep and eslint-plugin-security on every commit, plus a test suite dedicated to security invariants.
05 / FAQ
Questions, answered.
Does gup replace winget, brew or npm?
No. gup orchestrates each tool's native commands (winget upgrade, brew outdated, npm update -g, pip list --outdated…) behind one interface. No invented protocol, no version cache.
Does it work on macOS and Linux?
Yes. On macOS natively: Homebrew formulae and casks, MacPorts and the Mac App Store, on Apple Silicon and Intel. On Linux, Homebrew/Linuxbrew and Nix cover the OS level, and a binary installed by the distribution is handed back to apt or dnf. Everything above the OS layer — npm, pip, cargo, helm, VS Code… — behaves the same on all three systems.
How do I install gup?
npm install -g @charles_lindecker/gup --allow-scripts=node-pty, then gup doctor to see which providers are detected. Requires Node.js 26.9.0 or later. --allow-scripts=node-pty approves the install scripts of node-pty, which powers the embedded terminal: without it, npm 11 warns and npm 12 skips them.
Can I use gup in CI?
Yes. gup list --json --fast gives machine-readable output and gup update --all -y skips every prompt. Exit codes are stable: 0 success, 1 partial failure, 2 invalid arguments.
How many package managers does gup cover?
153 providers, one isolated module each: winget, scoop, chocolatey, Homebrew, MacPorts, npm, pnpm, pip, uv, cargo, gem, composer, dotnet tools, helm, kubectl, terraform, VS Code extensions, JetBrains IDEs, WSL distributions and more.
Is it safe to run?
Every subprocess goes through one entry point as a strict argument vector — never through a shell — with an allowlist pinned by tests. CodeQL, Semgrep, gitleaks, audit-ci and Dependabot run continuously. gup sends no telemetry.
How is it different from topgrade?
topgrade runs updates; gup first answers “what is outdated, from which version to which”. The scan is a separate step with JSON output, package-by-package selection, provider:package targets, per-package schedules and a local history you can review.
Which language is the interface in?
English by default. gup language fr switches it to French and saves the choice; GUP_LANG=fr does the same for a single shell and takes precedence over it. Commands, flags and JSON output are language-neutral, and this site is available in eight languages.
06 / INSTALL
Thirty seconds, and you know everything.
One npm install, one command, and the full list of what is outdated on your machine.
npm install -g @charles_lindecker/gup --allow-scripts=node-pty
gupFull-screen interfacegup list --fastWhat is outdated, fast scangup update --all -yEverything, no prompt (CI)gup update brew:fzfOne package, no scangup doctorWhat is detected, and how to install the rest
