dbpm
See Convention-Driven SQL Generation for generating standalone install and versioned upgrade scripts from Git changes.
dbpm is a package manager for Oracle database applications and reusable PL/SQL components.
The goal is to bring modern dependency management, versioning, packaging, and deployment workflows to Oracle database development.
Visit the dbpm website for product documentation and the package registry for published package metadata.
Installation
dbpm requires Python 3.11 or newer. Install the command in an isolated
environment with pipx:
pipx install dbpm
dbpm --version
uv users can install the same PyPI package with:
uv tool install dbpm
Installing into an existing Python environment with python -m pip install dbpm is also supported.
Database deployment commands require access to an Oracle database and an
Oracle-compatible command-line runner. Set DBPM_SQL_RUNNER to
SQLcl (the
sql executable) or SQL*Plus. Core is dbpm's in-database deployment substrate;
run dbpm check-core before managed deployments, or use dbpm bootstrap-core
for an empty schema. See Getting Started for database
connection setup.
Vision
dbpm aims to make Oracle database development feel more like modern software engineering ecosystems such as:
- Maven
- npm
- Cargo
- pip
while remaining Oracle-native and deployment-friendly.
Maven-compatible repositories may be useful for publishing immutable package artifacts, but dbpm should not require ordinary package consumers to understand Maven or install a JDK. Consumer installs should use dbpm's own CLI and plain HTTP(S) artifact retrieval where possible.
Goals
- Package reusable PL/SQL libraries
- Deploy end-user Oracle database applications through the same package workflow
- Resolve dependencies automatically
- Support semantic versioning
- Enable repeatable deployments
- Use Core as the in-database install registry and deployment substrate
- Support schema evolution
- Inject deployment provenance from package artifacts
- Lock deployments to immutable artifact identities
- Simplify CI/CD integration
- Reduce fragile hand-managed deployment scripts
Example
dbpm check-core --minimum-version 3.2.0
dbpm plan gh-maven:rsantmyer/simple_scheduler:com.512itconsulting.database:simple_scheduler:1.1.0 --mode install --dependency-source gh-maven:512itconsulting/utl_interval:com.512itconsulting.database:utl_interval:1.0.0
dbpm lock gh-maven:rsantmyer/simple_scheduler:com.512itconsulting.database:simple_scheduler:1.1.0 --dependency-source gh-maven:512itconsulting/utl_interval:com.512itconsulting.database:utl_interval:1.0.0
dbpm install --lockfile dbpm-lock.json
For a guided setup, see Getting Started. See the changelog for release contents and release checklist for the versioning process.
Features
- Package manifests through
dbpm.yaml,dbpm.yml,dbpm.json, orpackage.dbpm.yaml - Workspace manifests through
dbpm-workspace.yamlfor repositories with multiple package roots - Local package directory sources
- Local ZIP package sources
- GitHub Maven ZIP package sources with
gh-maven:owner/repo:group:artifact:version[:extension] - Generic Maven ZIP package sources with
maven:repository-url::group:artifact:version[:extension] - dbpm registry sources with
registry:package@constraint - HTTPS ZIP artifact sources for lockfile installs
- Maven snapshot ZIP resolution through
maven-metadata.xml - SHA-256 checksum capture for ZIP artifacts and deterministic TREE-SHA-256 capture for local directories
- Content-addressed artifact cache keyed by SHA-256 for lockfile-verified downloads
- Exact and caret-compatible dependency constraints
- Ordered multi-package install, conservative upgrade, and validate for dependency sources
- Dependency lockfile generation and verification through
dbpm lock - Lockfile-driven install without restating package sources
- Core-backed installed-state lookup
- Core-backed reverse-dependency lookup
- Core provenance staging through
pkg_application.stage_deployment_provenance_p - Core
DEPLOY_LOCKED-aware deployment policy - Install, upgrade, reinstall, resume, and validate workflows
- Read-only planning for manifest-declared composable runtimes (
runtime:indbpm.yaml), including isolated dependency payload paths and command exports beneath a root-application prefix. Filesystem staging and activation remain in progress (see spec/runtime-component.md). - ZIP artifact publishing to GitHub Packages and generic Maven repositories
- GPG artifact signing and lockfile-driven signature verification
- dbpm registry source resolution and artifact metadata indexing
Known Limitations
- Multi-package dependency execution does not support
reinstall. - Application-owned runtime composition, isolated dependency payloads, and
declarative command exports support install execution with isolated staging,
package-local scripts, export validation, payload promotion, command-link
activation, and an application receipt. Runtime validate reconciles the
receipt, payload identities, managed links, executable targets, and package
health scripts. Runtime resume can retry a matching incomplete staged
generation. Runtime upgrade retains prior versioned payloads, and reinstall
reconstructs same-version payloads with recovery backups. The active and
immediately prior generation are retained; unreachable older payloads and
recovery metadata are garbage-collected after activation. Uninstall removes
dbpm-owned runtime state while preserving operator data, and rollback
reactivates only database-compatible retained generations. The removed
package-owned fields
runtime.name,runtime.home_env,runtime.into, andruntime.layoutare rejected. - Lockfile database provenance reconciliation requires Core 3.3.0 or newer.
- Non-lockfile installs use the coordinate-based cache without checksum verification; the lockfile path has full SHA-256 verification.
Roadmap
- APEX integration
- Registry search/info commands and compatibility-aware registry resolution
Status
Live-tested against GitHub Packages artifacts for:
coreutl_intervalsimple_scheduler
simple_scheduler depends on utl_interval; dbpm can install both from GitHub Packages in dependency order and record Core provenance with artifact URLs and SHA-256 checksums.
Environment
Database and GitHub Packages access is configured through a local,
uncommitted shell environment file. Start from the committed
dbpm-env.sh.example template:
cp dbpm-env.sh.example dbpm-env.sh
chmod 600 dbpm-env.sh
Common variables:
DBPM_SQL_RUNNER: SQLcl or SQL*Plus executable, such assqlDBPM_CONNECT: raw Oracle connect string, such asuser/password@serviceDBPM_CONNECT_NAME: SQLcl saved connection name local to the invoking OS user. Mutually exclusive withDBPM_CONNECT; requires SQLcl as the runner.DBPM_GITHUB_TOKEN: GitHub token with package read accessDBPM_GITHUB_USER: optional GitHub username for package authenticationDBPM_SIGNING_KEY: optional default GPG key ID, fingerprint, or email fordbpm publishDBPM_MAVEN_TOKEN: token for generic Maven publishing targetsDBPM_MAVEN_USER: optional username for generic Maven publishing targetsDBPM_REGISTRY_URL: optional default registry URL, default:https://registry.dbpm.ioDBPM_REGISTRY_TOKEN: bearer token for registry indexingDBPM_REGISTRY_PUBLISHER: optional registry publisher overrideDBPM_REGISTRY_DESCRIPTION: optional registry description overrideDBPM_CACHE_DIR: optional local artifact cache directory, default:~/.dbpm/cacheDBPM_LOG_DIR: optional execution log directory, default:.dbpm-logsin the current working directoryDBPM_RUN_DB_TESTS: optional1to enable live database pytest tests
For SQLcl saved connections, do not put the saved connection name in
DBPM_CONNECT. Unset DBPM_CONNECT and set DBPM_CONNECT_NAME instead:
unset DBPM_CONNECT
export DBPM_CONNECT_NAME="Development Database (APP_USER)"
export DBPM_SQL_RUNNER=sql
Commands
| Command | Description |
|---|---|
dbpm init |
Scaffold a new package or workspace directory |
dbpm check-core |
Verify Core is installed and meets a minimum version |
dbpm plan |
Generate and print a deployment plan without executing |
dbpm lock |
Write or verify a dependency lockfile |
dbpm bootstrap-core |
Install Core into an empty schema |
dbpm install |
Install a package not yet registered in Core |
dbpm upgrade |
Upgrade an installed package to a higher version |
dbpm reinstall |
Destructively reinstall a package |
dbpm resume |
Resume a running or failed deployment |
dbpm validate |
Run a package's validation script |
dbpm uninstall |
Remove an application and its managed runtime |
dbpm rollback |
Reactivate a database-compatible retained runtime generation |
dbpm generate-scripts |
Generate standalone Oracle install and upgrade scripts from Git changes |
dbpm publish |
Build and publish a package to a Maven repository with GPG signing |
dbpm registry index |
Index a published immutable artifact in a dbpm registry |
dbpm workspace list |
List packages declared by a workspace manifest |
Run dbpm <command> --help for a quick flag reference. See docs/commands/source-types.md for the full source and version constraint syntax.
Related Projects
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file dbpm-1.4.1.tar.gz.
File metadata
- Download URL: dbpm-1.4.1.tar.gz
- Upload date:
- Size: 122.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6b6df61f21c480fb65a8629246e98fa219926827a946fbc81676aacb4ca3c9a6
|
|
| MD5 |
64744ea0d48e92d47bb83c654f7decca
|
|
| BLAKE2b-256 |
c0d084dfed0349e5f6cc3f84da424264bc69428bf444ad4d5f35a46ceede16fa
|
Provenance
The following attestation bundles were made for dbpm-1.4.1.tar.gz:
Publisher:
release.yml on 512itconsulting/dbpm
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
dbpm-1.4.1.tar.gz -
Subject digest:
6b6df61f21c480fb65a8629246e98fa219926827a946fbc81676aacb4ca3c9a6 - Sigstore transparency entry: 2302260653
- Sigstore integration time:
-
Permalink:
512itconsulting/dbpm@44e163bddbe8ced65f1307947daa6b07b1c1754f -
Branch / Tag:
refs/tags/v1.4.1 - Owner: https://github.com/512itconsulting
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@44e163bddbe8ced65f1307947daa6b07b1c1754f -
Trigger Event:
release
-
Statement type:
File details
Details for the file dbpm-1.4.1-py3-none-any.whl.
File metadata
- Download URL: dbpm-1.4.1-py3-none-any.whl
- Upload date:
- Size: 82.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
74a343f1168ab12c3c671769fbc692ecdfb3034cd77a092631407549201c2806
|
|
| MD5 |
ea75dcb8912a26f6dfd0879b0e68fbce
|
|
| BLAKE2b-256 |
0734919807f0a7f8e91d86d4720a75cdc45713d40829a18645d43314fff019b8
|
Provenance
The following attestation bundles were made for dbpm-1.4.1-py3-none-any.whl:
Publisher:
release.yml on 512itconsulting/dbpm
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
dbpm-1.4.1-py3-none-any.whl -
Subject digest:
74a343f1168ab12c3c671769fbc692ecdfb3034cd77a092631407549201c2806 - Sigstore transparency entry: 2302260699
- Sigstore integration time:
-
Permalink:
512itconsulting/dbpm@44e163bddbe8ced65f1307947daa6b07b1c1754f -
Branch / Tag:
refs/tags/v1.4.1 - Owner: https://github.com/512itconsulting
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@44e163bddbe8ced65f1307947daa6b07b1c1754f -
Trigger Event:
release
-
Statement type: