Bumply

Update your dependencies.Undo anything.

Bumply is a Mac app for keeping npm, pnpm, Yarn, and Bun projects current. It shows you every command before it runs, backs up your manifest and lockfile byte-for-byte, and rolls back the moment anything fails.

Download for free

Download Bumply

Version 1.10 for macOS 13 and later. Free for three projects.

Buy Bumply

Version 1.10 for macOS 13 and later. Free for three projects.

Bumply - Update your dependencies and undo anything | Product Hunt
Bumply showing a pnpm workspace: package manager, Node runtime, compatibility status, and a security audit panel

What Bumply does

Updates you can undo

The exact command is shown before it runs, and your manifest and lockfile are copied before it touches them. If the update fails they go back byte-for-byte. If you change your mind a week later, Update History lists every update the project has had and puts those two files back then — and Bumply never writes to your git history.

Bumply’s update confirmation: the npm command in full, and a preflight reporting that the protected files are clean and git has no pending manifest or lockfile changes

Dependency health, with the evidence

What is installed, what your manifest asks for, and what the registry offers, each with its source. Every update says whether it stays inside your range or crosses a major.

A dependency expanded in Bumply, showing its declared range, the installed version, the compatible target and the registry’s latest, each labelled with where it came from

Audits that never execute code

Advisories come from your package manager’s audit data, read-only: package-lock-only and ignore-scripts. Nothing is installed and no package script runs while Bumply looks.

Bumply’s project view: a security audit that has not run yet, saying nothing is sent automatically, above a list of recommended updates marked minor or patch in range

The gigabytes you forgot about

Bumply finds the build artefacts a project can rebuild from scratch — node_modules, .next, .turbo, Pods — and what each costs. Anything it removes goes to the Trash.

Bumply’s Project Storage: twenty gigabytes across twenty-four items, each build artefact listed with its size and marked regenerable or worth checking first

All 42 things Bumply does

  • Finds the Node projects under folders you pick
  • npm, pnpm, Yarn and Bun
  • Monorepos count as one project
  • Every project in one window, sorted and filtered
  • Exclude anything you would rather it left alone
  • Says why a folder was not picked up
  • Finds Node itself, even installed through nvm

Or keep doing it by hand

  • YesHandled
  • PartlyPossible, with effort
  • NoOn you
Bumply
By hand

Seeing what changed

Every project at once
YesOne window, whatever manager each uses
NoOne terminal, one project at a time
Installed, declared and published, side by side
YesEach with its source
PartlyThree places to look, then compare
Inside your range, or across a major
YesClassified per update
PartlyRead the range, do the semver
Advisories without running package code
Yespackage-lock-only, ignore-scripts
PartlyOnly if you remember the flags

Changing things

The exact command, before it runs
YesShown in full, waits for you
YesYou typed it
Manifest and lockfile copied first
YesEvery time, restored byte-for-byte
NoIf you thought of it
Refuses to start on a dirty repository
YesNames the file and stops
NoYou find out during the restore
A way back days after the update
YesUpdate History, per project
NoWhatever you thought to copy
When another dependency blocks the update
YesNamed, with the command, then re-checked
PartlyRead the error, work out the order

Reclaiming disk

What each build artefact is costing
YesPer project, measured
Partlydu -sh, then a judgement call
Removals go to the Trash
YesRecoverable
Norm -rf is final

What it costs

Perpetual licence

once

One payment. No subscription, no account, nothing recurring.

  • A perpetual licence: it does not expire, and nothing stops working if you never pay again.
  • Twelve months of updates from the day you buy. After that you stay on the last version released inside your window, and renewing is optional.
  • Three Macs at a time, and moving to a new one is a click: removing the licence from a Mac frees its place.
  • Free for three projects, with no time limit and no account. Bumply does not stop working if you never buy this — a licence is what lifts the limit.
  • The first seven days cover every project you have, so you can judge it on all of your work rather than three of it.
  • Thirty days to change your mind, no reason required.

Questions

What do I get without paying?

Three projects, for as long as you like. Bumply watches the three oldest projects in your list for free, with no account and no expiry: it does not stop working, nothing is deleted, and there is no wall to hit. For the first seven days every project is covered instead of three, so you can try it on all of your work before deciding. A licence lifts the limit for good.

Does Bumply need an internet connection?

It works offline. It contacts our server once, when you activate, and never again about your licence. It does run your package manager, and that contacts its own registry from your Mac to find out what is outdated — exactly as it does when you run it in a terminal. Those requests go to the registry, not to us.

Does it work with monorepos?

Yes. A workspace root and the packages inside it are recognised as one project. The screenshot at the top of this page is a pnpm workspace with two packages.

What happens after the year of updates?

Nothing stops. The licence is perpetual — the year covers new versions, not the right to keep using the app. You stay on the last version released inside your window, and renewing is optional.

Can I install it on more than one Mac?

Three at a time — a desk machine, a laptop, and one spare. Reinstalling on a Mac you have already activated costs nothing, and when you are done with one, Remove from this Mac in Settings frees its place for the next. The limit is on how many run at once, not on how many you may ever own.