Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

depsmith

CI Coverage License: MIT

Prepare, review and apply dependency updates for a repository, from a Rust CLI or a typed Python API. Each target is resolved by its own package manager in a disposable copy of the repository. You review the exact file and dependency changes, and the reviewed files are then written without resolving again.

  • Supported: Pixi (pixi.toml, Pixi-managed pyproject.toml), GitHub Actions workflow references, Cargo (Cargo.lock owners), conda (environment.yml locked with conda-lock), uv (pyproject.toml with uv.lock) and npm (package.json with package-lock.json).
  • Safe by default: updates keep your constraints. Proposals go stale if the repository changes, and interrupted writes can be recovered.
  • Evidence-backed suggestions for pins that block newer releases, which you can accept in the same declaration style.
  • Optional vulnerability scanning compares before and after with one database snapshot. Packages it cannot assess are reported, never treated as clean.

📖 Documentation: the wiki

Install

pip install --pre depsmith         # Python 3.10+: CLI and Python API
cargo install depsmith             # build the CLI from crates.io (Rust 1.89+)
cargo binstall depsmith            # the release executable, via cargo-binstall
curl -fsSL https://github.com/ArjunRachithcf/depsmith/releases/latest/download/install.sh | sh

On Windows, irm https://github.com/ArjunRachithcf/depsmith/releases/latest/download/install.ps1 | iex. The install scripts download the release executable for your platform, verify it against the release's SHA256SUMS before installing anything, and install it to ~/.local/bin (%LOCALAPPDATA%\depsmith\bin on Windows); they never edit your shell startup files. While only release candidates are published, ask for one explicitly:

curl -fsSL https://github.com/ArjunRachithcf/depsmith/releases/download/v0.1.0-rc.2/install.sh | sh -s -- --version v0.1.0-rc.2
$env:DEPSMITH_VERSION = "v0.1.0-rc.2"
irm https://github.com/ArjunRachithcf/depsmith/releases/download/v0.1.0-rc.2/install.ps1 | iex

Other options: --pre (newest release including pre-releases), --prefix DIR ($env:DEPSMITH_PREFIX), and --help.

Then depsmith init checks the native tools your targets use and offers to install the missing ones. See Getting started.

Quick start

depsmith discover --root path/to/project
depsmith check    --root path/to/project --target pixi:pixi.toml
depsmith update   --root path/to/project --target pixi:pixi.toml

check writes nothing and exits 1 when updates are pending. update shows the changes and asks before applying. In CI, add --apply --yes --non-interactive --json (CI integration).

from depsmith import UpdateOptions, prepare

proposal = prepare(
    "path/to/project", targets=["pixi:pixi.toml"], options=UpdateOptions()
)
for change in proposal.changes:
    print(change.diff)
if not proposal.failures:
    proposal.apply()

Learn more

Topic Page
Saved targets and options (depsmith.toml) Configuration
Proposals, stale inputs, partial apply, recovery Reviewing and applying
Pixi updates, upgrades, suggestions, --accept Pixi adapter
Actions release lines and commit pins GitHub Actions adapter
Cargo lock owners, MSRV-aware updates Cargo adapter
conda-lock environments, sharded repodata Conda adapter
uv workspaces, Git pins, index evidence uv adapter
npm workspaces, cooldowns, registry evidence npm adapter
Grype scanning, identities, policy, suppressions Vulnerability scanning
Common errors Troubleshooting
Every command and option CLI reference
The Python API Python API

The wiki is generated from docs/wiki/, and its terms follow the glossary in CONTEXT.md.

Status

Alpha. The first release will be published to PyPI and as GitHub release binaries, with conda-forge after that (Releasing). Post-install project checks and interactive suggestion prompts are planned. New package managers plug in through one adapter module and a shared conformance suite (Architecture).

Contributing

See Development and testing and Architecture. Install the hooks with prek install --hook-type pre-commit --hook-type pre-push. Changes land through pull requests with signed commits.

License

MIT

Metadata

Release files for depsmith 0.1.0rc2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for depsmith 0.1.0rc2
File Size Uploaded
depsmith-0.1.0rc2.tar.gz 213.6 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for depsmith 0.1.0rc2
File
depsmith-0.1.0rc2-cp310-abi3-win_amd64.whl CPython 3.10 abi3 Windows x86-64 Details
depsmith-0.1.0rc2-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.10 abi3 Linux glibc 2.17+ x86-64 Details
depsmith-0.1.0rc2-cp310-abi3-macosx_11_0_arm64.whl CPython 3.10 abi3 macOS 11.0+ ARM64 Details
depsmith-0.1.0rc2-cp310-abi3-macosx_10_12_x86_64.whl CPython 3.10 abi3 macOS 10.12+ x86-64 Details

Total release size: 17.7 MB

Release files / depsmith-0.1.0rc2.tar.gz

Download URL depsmith-0.1.0rc2.tar.gz
Size 213.6 kB
Tags Source
SHA-256 checksum
How to use checksums
01116c680a1d3e76d964c4c36c37cbdc22d46d2856d1d79b7ced814c045a93e4
BLAKE2b-256 checksum
How to use checksums
1d1566943314cc4f547b20b69e9ba26515dc11e78394bcd55144dbc21d34438e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release files / depsmith-0.1.0rc2-cp310-abi3-win_amd64.whl

Download URL depsmith-0.1.0rc2-cp310-abi3-win_amd64.whl
Size 4.1 MB
Tags CPython 3.10 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
d5c86aa5abfcc69d6b546db103bc70d59f1a5b548e92948235226c93b1aeb88f
BLAKE2b-256 checksum
How to use checksums
d8be7c62ff4f0665943ccd4c7fd708261722a7a15fd49fcff2673219605b0a48
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release files / depsmith-0.1.0rc2-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL depsmith-0.1.0rc2-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 4.8 MB
Tags CPython 3.10 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
30fe787000f37eff687c2726d547b0ad31048741a835f7ebe5715dc0fcd36de5
BLAKE2b-256 checksum
How to use checksums
b03b58426bd8a5472dfbd0f017896dd4e6c6093a77d460e569739b111b524ce6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release files / depsmith-0.1.0rc2-cp310-abi3-macosx_11_0_arm64.whl

Download URL depsmith-0.1.0rc2-cp310-abi3-macosx_11_0_arm64.whl
Size 4.2 MB
Tags CPython 3.10 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
508fd1a201dab1a85fafc153eaf08a4663dcfd85f8ff9d83e3ad18c6ccc6a939
BLAKE2b-256 checksum
How to use checksums
5c6c2c66ae38e88771bfb51c1815fcc06873bdc30c2d99168654ffe9adc3742d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release files / depsmith-0.1.0rc2-cp310-abi3-macosx_10_12_x86_64.whl

Download URL depsmith-0.1.0rc2-cp310-abi3-macosx_10_12_x86_64.whl
Size 4.4 MB
Tags CPython 3.10 abi3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
50f4c2c344287148966fbc0b8e6dc5342496dc4a22d9bca2d3e721598daa941b
BLAKE2b-256 checksum
How to use checksums
1296d3993e9457f4b3f2f7cd8b270f1970d85ff7b75281842ed6880cdbb1d920
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0rc2 This release

5 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page