Python pipx¶
- ID
pipx- Links
- Upstream stars
⭐ 12,973
- Last commit
2026-09-28
- Version requirement
>= 1
- Cooldown
✓
- Platforms
🅱️ BSD · 🐧 Linux · 🍎 macOS · ⨂ Unix · 🪟 Windows
- Operations
installed·outdated·install·upgrade·upgrade_all·remove- purl types
pkg:pipx/·pkg:pypi/- CLI name
pipx- Issues and PRs
- Source
pipx installs Python CLI applications, each in its own isolated venv.
Note
The supply-chain cooldown rides on the underlying pip and needs that pip
to be at least 26.1, the first release to honor
--uploaded-prior-to; older pip silently ignores the release-age gate.
What mpm adds to pipx¶
mpm reaches across every manager at once, not pipx alone: mpm installed and mpm outdated cover pipx alongside pip, pipxu, uv, uvx and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your pipx commands, in mpm¶
You already know pipx: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Install a package |
|
|
Remove a package |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
Only each venv’s main package is tracked, never the packages injected beside it. |
|
✅ |
On pipx older than |
|
||
|
❌ |
The request was closed as not planned (pypa/pipx#777): PyPI exposes no search API and custom search is out of pipx’s scope. |
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
||
|
||
|
Configuration¶
Ignore
pipxon thempmCLI by passing the--no-pipxoption.Ignore it for every run in your configuration:
[mpm] pipx = false
Raise the timeout of all
pipxcalls:[mpm.overrides.pipx] timeout = 900
Run
mpm config-template pipxto print all overridable settings for your configuration file:[mpm.overrides.pipx] cli_names = [ "pipx", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [] pre_cmds = [] requirement = ">=1.0.0" stop_on_error = false unmaintained = false version_cli_options = [ "--version", ] version_regexes = [ "(?P<version>\\S+)", ]
Recipes¶
A few jobs you would otherwise script around pipx, one mpm command each:
Snapshot and clone a machine:
mpm --pipx dump pipx.toml, thenmpm restore pipx.tomlon the next one.Export a compliance SBOM:
mpm --pipx sbom(CycloneDX by default,--spdxfor SPDX).
Privilege escalation¶
mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.
None of its operations is privileged.
See privilege escalation for the full policy.
Cooldown¶
mpm natively enforces its release-age cooldown on Python pipx, injecting the PIP_UPLOADED_PRIOR_TO environment variable on every call. Point it at a window (mpm --cooldown 7 --pipx upgrade --all) to skip anything published in the last 7 days: a guard against a compromised or yanked fresh release landing before anyone notices.
Status: ✅ Enforced (via pip’s env var; needs the underlying pip ≥ 26.1)
Mechanism: inherits
PIP_UPLOADED_PRIOR_TOReference: pypa/pipx#1811
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Python pipx well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ pipx list --json
{
"pipx_spec_version": "0.1",
"venvs": {
"pycowsay": {
"metadata": {
"injected_packages": {},
"main_package": {
"app_paths": [
{
"__Path__": "~/.local/pipx/venvs/pycowsay/bin/pycowsay",
"__type__": "Path"
}
],
"app_paths_of_dependencies": {},
"apps": [
"pycowsay"
],
"apps_of_dependencies": [],
"include_apps": true,
"include_dependencies": false,
"package": "pycowsay",
"package_or_url": "pycowsay",
"package_version": "0.0.0.1",
"pip_args": [],
"suffix": ""
},
"pipx_metadata_version": "0.2",
"python_version": "Python 3.10.4",
"venv_args": []
}
}
}
}
$ pipx list --outdated --output=json
{
"command": ["list"],
"data": {
"packages_checked": 1,
"packages": [
{
"environment": "pycowsay",
"package": "pycowsay",
"version": "0.0.0.1",
"latest_version": "0.0.0.2",
"injected": false,
"pinned": false
}
],
"skipped": []
},
"errors": [],
"exit_code": 0,
"pipx_result_version": "1",
"status": "success"
}
$ pipx runpip pycowsay list --no-color --format=json --outdated > --verbose --quiet
[
{
"name": "pycowsay",
"version": "0.0.0.1",
"location": "~/.local/pipx/venvs/pycowsay/lib/python3.10/site-packages",
"installer": "pip",
"latest_version": "0.0.0.2",
"latest_filetype": "wheel"
}
]
Version check¶
The version is extracted from the output of pipx --version with:
r"(?P<version>\S+)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
7.3.0(2026-07-17)outdatednow relies on pipx’s nativepipx list --outdatedquery on pipx1.16.0and newer: all venvs are checked in a single call, each by its own backend (pip or uv). Older pipx keeps the previous per-venv pip probes.
5.4.0(2022-06-29)Implement
outdatedoperation.
5.2.0(2022-06-16)Add
removeoperation.
5.1.0(2022-05-15)Add
pipxsupport. Closes #468.