depchk
Python dependency version checker for Poetry projects. Analyzes pyproject.toml and provides upgrade recommendations with risk assessment and Python compatibility checks.
What It Does
- Checks PyPI for the latest most compatible versions of your dependencies
- Risk-scores each update (HIGH/MEDIUM/LOW) based on version jumps and Python compatibility
- Respects constraints from local path dependencies (monorepos, git submodules)
- Validates recommended versions and their support for your target Python version
- Creates a backup before modifying your
pyproject.toml - JSON output for automation and CI/CD
Quick Start
Install Depchk
Install Depchk with pipx to run it as a standalone tool without affecting your system Python:
pipx install depchk
Or with pip in a virtual environment:
pip install depchk
Tip:
pipxis recommended for global CLI tools as it provides isolated environments.
Or with Poetry (for development):
git clone https://github.com/bulletinmybeard/depchk.git
cd depchk
poetry install
# Analyze your project
depchk /path/to/pyproject.toml
# Preview what will change (creates pyproject.toml.updated.toml)
depchk
# Apply updates directly (creates backup first)
depchk --update-source-file
CLI Commands
| Command | Description |
|---|---|
depchk |
Analyze current directory's pyproject.toml |
depchk PATH |
Analyze specific pyproject.toml |
depchk --update-source-file |
Apply updates directly (creates backup) |
depchk --target-python "^3.13" |
Override Python version for testing |
depchk --allow-prerelease |
Include pre-release versions |
depchk --ignore-local-deps |
Skip local dependency constraints |
depchk --json |
JSON output for automation |
depchk --verbose |
Show debug information |
Note:
--jsonand--verboseare mutually exclusive. Using both will exit with a JSON error.
Automation
depchk supports JSON output for scripting and CI/CD. All JSON responses use a standardized envelope:
# Check response status
depchk --json | jq '.status'
# Output: "success"
# Get update recommendations
depchk --json | jq '.data.updates'
# Check summary programmatically
depchk --json | jq '.data.summary'
# Test against a different Python version
depchk --target-python "^3.13" --json
JSON Response Structure:
{
"status": "success",
"data": {
"updates": {"httpx": "^0.28.1", ...},
"summary": {"analyzed": 15, "updated": 8, ...},
"report": [...]
}
}
Error responses use the same envelope:
{
"status": "error",
"error": {"code": "incompatible_flags", "message": "..."}
}
Configuration
depchk uses a ~/.depchk/config.yaml file for persistent settings:
analysis:
cache_ttl_hours: 24
allow_prerelease: false
Config file locations (checked in order):
- Project directory:
./config.yaml - User home:
~/.depchk/config.yaml
Override with environment variables: DEPCHK_CACHE_TTL, DEPCHK_ALLOW_PRERELEASE.
Priority: CLI flags > Environment variables > Config file > Defaults
Example Output
+------------------------------------------+
| Dependency Analysis Report |
| Python Version: ^3.12 |
+------------------------------------------+
Summary
* Analyzed: 15
* Updates available: 8
* Skipped: 2
Recommended Updates
| Package | Current | -> | Recommended | Python | Risk |
|-----------|---------|-----|-------------|-----------|------|
| httpx | ^0.25.0 | -> | ^0.28.1 | 3.8->3.13 | MED |
| fastapi | ^0.115 | -> | ^0.118.3 | 3.8->3.13 | LOW |
! Risk Factors:
* httpx:
- Minor version jump (^0.25.0 -> ^0.28.1)
Local Path Dependency Support
How It Works
depchk handles local path dependencies (monorepos, git submodules) by enforcing their version constraints as "ceilings":
- Detects local path dependencies in your
pyproject.toml - Reads their Python and package requirements
- Ensures recommendations stay compatible with all local deps
Example: If your local dependency requires httpx: ^0.25, depchk will NOT recommend httpx: ^0.28 even if it's available.
Monorepo Example
my-company/
+-- api/pyproject.toml # python = "^3.12", httpx = "^0.27.0"
+-- shared-utils/pyproject.toml # python = "^3.12", httpx = "^0.25.0" <- ceiling
When analyzing api/, depchk respects the ^0.25.0 constraint from shared-utils.
Use --ignore-local-deps to analyze independently without constraint enforcement.
Shell Integration (Development Only)
Note: This section is only relevant if you run depchk from the cloned repo via
poetry run.
This optional wrapper function provides a convenient depchk shortcut when running from a cloned repo.
Linux/macOS (ZSH/Bash)
Create ~/depchk_shell.sh:
depchk() {
local project_dir="$HOME/path/to/depchk"
local original_dir="$PWD"
if [[ ! -d "$project_dir" ]]; then
echo "Error: depchk project not found at $project_dir"
return 1
fi
if [[ $# -eq 0 ]] || [[ "$1" == -* ]]; then
(cd "$project_dir" && poetry run depchk "$original_dir/pyproject.toml" "$@")
else
(cd "$project_dir" && poetry run depchk "$@")
fi
}
Then add to ~/.zshrc or ~/.bashrc:
[ -f "$HOME/depchk_shell.sh" ] && source "$HOME/depchk_shell.sh"
Reload: source ~/.zshrc
Risk Assessment
Each update is scored based on:
- Version jump impact: Major > Minor > Patch
- Python compatibility: Checks
requires_pythonmetadata from PyPI - Classifier data: Extracts tested Python versions
Confidence levels:
- LOW: Patch/minor updates with full Python compatibility
- MEDIUM: Minor version jumps or limited compatibility data
- HIGH: Major updates with potential compatibility issues
Requirements
- Python 3.12+
- Poetry for dependency management
- A Poetry project (
pyproject.tomlwith[tool.poetry]section)
Links
License
MIT License - see the LICENSE file for details.
Metadata
Release files for depchk 0.9.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| depchk-0.9.5.tar.gz | 41.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| depchk-0.9.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 84.2 kB
Release files / depchk-0.9.5.tar.gz
| Download URL | depchk-0.9.5.tar.gz |
|---|---|
| Size | 41.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d770e0ca250dc588de178de5a4a8d9f82a1e540b34dde8db994de5b95c3ce26a
|
|
BLAKE2b-256 checksum How to use checksums |
d76edab70babac74bc20d599beec0e3046e83db3cc375248b064c09086b66d8c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/2.1.4 CPython/3.12.12 Linux/6.11.0-1018-azure
|
Release files / depchk-0.9.5-py3-none-any.whl
| Download URL | depchk-0.9.5-py3-none-any.whl |
|---|---|
| Size | 43.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a6c3493e9acaac0bd242b94e0ee484b4fda232ea1c9af7cb710ccc6b9a8e7285
|
|
BLAKE2b-256 checksum How to use checksums |
2c51970972a28e4b297d72d86e91303622d997eb641f478868034f284a22b09b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/2.1.4 CPython/3.12.12 Linux/6.11.0-1018-azure
|