Skip to content
Steven Barash

Uptick

A Zed extension for dependency updates and known vulnerability context.

Role
Creator and primary developer
Status
Active
Technologies
Rust, Zed Extension API, Language Server Protocol, OSV

The extension and language server are public and actively developed.

OSV results are useful context, not a complete security scan. Uptick does not claim to find every dependency or vulnerability.

Extension and analysis path
  1. Dependency file in Zed
  2. Thin Zed extension
  3. Rust language server
  4. Registry data + OSV

Hints, diagnostics, links, and update actions through LSP

Why Uptick exists

I wanted to see outdated and vulnerable dependencies in Zed instead of switching to another tool.

Uptick is for people who work in Zed and want version and vulnerability details beside the dependencies they are already editing.

Inside the extension

  • The Zed extension is intentionally thin. A Rust language server handles registry lookups and vulnerability analysis.
  • The language server returns version hints, diagnostics, links, and update actions through the Language Server Protocol.
  • Uptick supports package.json, Cargo.toml, pubspec.yaml, composer.json, go.mod, and pom.xml.
  • The editor integration must fit Zed’s extension model while the analysis needs native networking and parsing code.

Editor integration

  • Splitting the extension from the language server adds installation work, but keeps editor integration separate from dependency analysis.
  • Uptick presents registry and OSV data in the editor rather than trying to replace a dedicated dependency or security tool.
Back to projects
Start