// Reference

Languages

Upseam supports JavaScript, TypeScript, Python and Go. SDK detection covers their manifests and lockfiles only.

SDK versions

The SDK version comes from the lockfile or the manifest, up to three directories deep:

Language Files read
JavaScript, TypeScript package.json, then the npm, yarn or pnpm lockfile next to it
Python requirements*.txt, then pyproject.toml, Pipfile, poetry.lock and uv.lock, first match wins
Go go.mod: require lines and blocks, replace directives

In JavaScript, the SDK must be listed in dependencies or devDependencies of a package.json. Its version is read from package-lock.json, yarn.lock or pnpm-lock.yaml in the same directory; without one, it is the first version number in the package.json range (^16.2.0 gives 16.2.0). A workspace lockfile in a parent directory is not used.

Pipfile.lock is not read. A Python requirement with an upper bound or an exclusion only, such as <3 or !=2.0, gives an unknown SDK version.

In Go, a module path with a major suffix (github.com/stripe/stripe-go/v82) matches the SDK, and its tag (v82.1.0) is the SDK version; +incompatible and pseudo-versions are read by their numeric part. A replace with a local path or another module gives an unknown version; a replace with another version of the same module gives that version. go.sum and go.work are not read. Only official Go SDKs are recognised, see Providers. In .go files a changed field also matches its Go names: current_period_end matches CurrentPeriodEnd, sink_sid matches SinkSid and SetSinkSid.

Rescans

A push to the default branch makes Upseam scan the repository again when it changes a manifest or lockfile (package.json, package-lock.json, yarn.lock, pnpm-lock.yaml, pyproject.toml, Pipfile, poetry.lock, uv.lock, requirements*.txt, go.mod, go.sum), .github/upseam.yml, or a source or spec file Upseam reads (for example .js, .ts, .py, .go, .graphql, .yaml, .json).

API version pins

The API version comes from the pin in code, for example apiVersion in JavaScript or stripe.api_version in Python; each provider lists its pins. Without a pin, the version is inferred from the SDK version and marked as inferred, but only for SDK releases Upseam has a default version for; otherwise the version is unknown.

Comments and imports

Comments are neither pins nor matches:

  • comment lines starting with //, # or *, and /* … */ blocks;
  • Python docstrings: a """ or ''' block at the start of a file or right after a def or class header.

Code after */ on the closing line is still code, and a block that never closes is not a comment. A comment after code on the same line, attribute docstrings and strings after imports are not recognised as comments. Lines that start with import or from, and lines inside a Go import (…) block, are not matches.

MCP configs and agent files

For MCP servers Upseam also reads JSON and JSONC MCP configs (comments and trailing commas allowed), Codex config.toml, Claude Code settings and agent instruction files in Markdown. Only the known file paths at the repository root are read.

Patches

The patch gates cover every supported language. Every changed JavaScript or TypeScript file must parse with the TypeScript compiler, every changed Python file must pass the Python lexer, and every changed Go file must pass the Go lexer. Go test files (_test.go) and go.mod are never patched, so a Go import path or module major bump always goes to a person. The allowed conversions and forbidden names differ per language; see Patch gates. Patches to MCP configs, settings and instructions may only switch a matched tool name; see MCP servers.