Skip to main content

Latest Version Python Versions Build Status Documentation Status

chill-out

chill-out

Have your dependencies chill out a bit while you make sure they are safe.

chill-out audits your lockfile for packages that are too fresh to trust. The lockfile is what actually gets installed, so that's what matters: a requests declared in pyproject.toml is only a real risk once it shows up in uv.lock. Maintainer tokens get stolen, typosquatters grab package names, and plenty of releases are just broken. Cooldown is the practice of refusing any version that has been public for less than some grace period, long enough for the community to spot trouble and react.

Supply chain attacks (compromised maintainer accounts, hijacked publishing tokens) typically surface as a brand-new release of a package. If your cooldown window is 14 days and you run chill-out before every deploy, a malicious release has to survive 14 days of public scrutiny before it can land in production. Transitives matter as much as direct dependencies, sometimes more, because you can't vet them by hand.

GitHub's Dependabot supports cooldown windows natively, but Dependabot only runs on the schedule you give it. chill-out runs on demand from your terminal, your CI, or your editor: it reads your lockfile, asks the registry when each package was published, and tells you which entries (principals and transitives alike) are still inside the cooldown window. When it can, it suggests an older version that is safely past its cooldown, or fixes your locked dependencies outright to eliminate the threat.

Super-quick start

Requires: Python 3.12+

pip install chill-out

In any npm or Python project:

chill-out check

To rewrite your manifest with safe pins:

chill-out fix

Documentation

The complete documentation lives at the chill-out home page.

Demo

To check out the features, run the demo directly via uvx without installing it!

uvx --from "chill-out[demo]" chill-out-demo

Metadata

Release files for chill-out 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for chill-out 0.1.0
File Size Uploaded
chill_out-0.1.0.tar.gz 78.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for chill-out 0.1.0
File Interpreter ABI Platform
chill_out-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 173.9 kB

Release files / chill_out-0.1.0.tar.gz

Download URL chill_out-0.1.0.tar.gz
Size 78.0 kB
Tags Source
SHA-256 checksum
How to use checksums
a52a1566c1d3917bfbeec7eba723323de399a7dad6d17d63ffe9aa5e4377382f
BLAKE2b-256 checksum
How to use checksums
8fabd0e9490b5a4402283903279870efd9f0df1e3ea70c33c53b0d571e640c29
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / chill_out-0.1.0-py3-none-any.whl

Download URL chill_out-0.1.0-py3-none-any.whl
Size 95.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5d786117f40fa525749a45223e69accf2291f1caf0e1068ed981a45a5a3ef2f4
BLAKE2b-256 checksum
How to use checksums
d6df5e3e0480501e4b487a38812971974c5fc0724f3eb560a07ba24f95b6cd5a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page