comparison
Twelve capabilities. Nine tools. Honest marks.
Including the rows where the others win — two of them are rows inup loses outright. Verified against each tool's own documentation on 2026-07-09.
10/12
inup
7/12
ncu
6/12
taze
3/12
PM built-ins
capabilityinupncutazePM built-ins
One tool for npm, yarn, pnpm & bun
Interactive upgrade UI
Monorepos & workspaces
Vulnerability audit in the pickeronly inup
Changelogs in the terminalonly inup
Search & dep-type toggles in the UIonly inup
pnpm catalogs, comments preserved
CI gate + JSON report
GitHub Action includedonly inup
Actively maintained (2026)
Doctor mode (test each upgrade)inup loses
Per-package upgrade rulesinup loses
"PM built-ins" = yarn upgrade-interactive,pnpm update -i, bun update -i,deno outdated -i — each works with its own package manager only, so the score counts a capability only where that built-in provides it for its own ecosystem.
head-to-heads
vs npm-check-updatesThe closest tool. Mature rules and doctor mode, no audit in the picker.vs tazeModern, catalog-aware, per-package rules. No audit, no changelogs.vs npm-checkFinds unused dependencies. Not published since July 2022.vs PM built-insOne per package manager, four to learn. No audit, no changelogs.vs RenovateAn always-on bot that opens PRs. inup is the local pass.vs DependabotGitHub's built-in bot. Hosted, scheduled, no interactive choice.vs updatesFast, multi-ecosystem, non-interactive. A checker, not a picker.vs npm-upgradeInteractive and changelog-aware, but npm-only and single-package.
Nothing to migrate.
inup reads the same manifests these tools do — no config file, no lockfile rewrite. Run it once and compare the output yourself.