chill-out
Have your dependencies chill out a bit while you make sure they are safe.
chill-out audits your lockfile for packages that are too fresh to trust. The lockfile is what actually gets installed,
so that's what matters: a requests declared in pyproject.toml is only a real risk once it shows up in uv.lock.
Maintainer tokens get stolen, typosquatters grab package names, and plenty of releases are just broken. Cooldown is
the practice of refusing any version that has been public for less than some grace period, long enough for the
community to spot trouble and react.
Supply chain attacks (compromised maintainer accounts, hijacked publishing tokens) typically surface as a brand-new
release of a package. If your cooldown window is 14 days and you run chill-out before every deploy, a malicious
release has to survive 14 days of public scrutiny before it can land in production. Transitives matter as much as
direct dependencies, sometimes more, because you can't vet them by hand.
GitHub's Dependabot supports cooldown windows natively, but Dependabot only runs on the schedule you give it.
chill-out runs on demand from your terminal, your CI, or your editor: it reads your lockfile, asks the registry when
each package was published, and tells you which entries (principals and transitives alike) are still inside the
cooldown window. When it can, it suggests an older version that is safely past its cooldown, or fixes your locked
dependencies outright to eliminate the threat.
Super-quick start
Requires: Python 3.12+
pip install chill-out
In any npm or Python project:
chill-out check
To rewrite your manifest with safe pins:
chill-out fix
Documentation
The complete documentation lives at the chill-out home page.
Demo
To check out the features, run the demo directly via uvx without installing it!
uvx --from "chill-out[demo]" chill-out-demo
Metadata
Release files for chill-out 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| chill_out-0.1.0.tar.gz | 78.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| chill_out-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 173.9 kB
Release files / chill_out-0.1.0.tar.gz
| Download URL | chill_out-0.1.0.tar.gz |
|---|---|
| Size | 78.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a52a1566c1d3917bfbeec7eba723323de399a7dad6d17d63ffe9aa5e4377382f
|
|
BLAKE2b-256 checksum How to use checksums |
8fabd0e9490b5a4402283903279870efd9f0df1e3ea70c33c53b0d571e640c29
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / chill_out-0.1.0-py3-none-any.whl
| Download URL | chill_out-0.1.0-py3-none-any.whl |
|---|---|
| Size | 95.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5d786117f40fa525749a45223e69accf2291f1caf0e1068ed981a45a5a3ef2f4
|
|
BLAKE2b-256 checksum How to use checksums |
d6df5e3e0480501e4b487a38812971974c5fc0724f3eb560a07ba24f95b6cd5a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|