This release is a pre-release and may not be stable for production use.
depsmith
Prepare, review and apply dependency updates for a repository, from a Rust CLI or a typed Python API. Each target is resolved by its own package manager in a disposable copy of the repository. You review the exact file and dependency changes, and the reviewed files are then written without resolving again.
- Supported: Pixi (
pixi.toml, Pixi-managedpyproject.toml), GitHub Actions workflow references, Cargo (Cargo.lockowners), conda (environment.ymllocked with conda-lock), uv (pyproject.tomlwithuv.lock) and npm (package.jsonwithpackage-lock.json). - Safe by default: updates keep your constraints. Proposals go stale if the repository changes, and interrupted writes can be recovered.
- Evidence-backed suggestions for pins that block newer releases, which you can accept in the same declaration style.
- Optional vulnerability scanning compares before and after with one database snapshot. Packages it cannot assess are reported, never treated as clean.
📖 Documentation: the wiki
Install
pip install --pre depsmith # Python 3.10+: CLI and Python API
cargo install depsmith # build the CLI from crates.io (Rust 1.89+)
cargo binstall depsmith # the release executable, via cargo-binstall
curl -fsSL https://github.com/ArjunRachithcf/depsmith/releases/latest/download/install.sh | sh
On Windows, irm https://github.com/ArjunRachithcf/depsmith/releases/latest/download/install.ps1 | iex.
The install scripts download the release executable for your platform, verify
it against the release's SHA256SUMS before installing anything, and install
it to ~/.local/bin (%LOCALAPPDATA%\depsmith\bin on Windows); they never
edit your shell startup files. While only release candidates are published,
ask for one explicitly:
curl -fsSL https://github.com/ArjunRachithcf/depsmith/releases/download/v0.1.0-rc.2/install.sh | sh -s -- --version v0.1.0-rc.2
$env:DEPSMITH_VERSION = "v0.1.0-rc.2"
irm https://github.com/ArjunRachithcf/depsmith/releases/download/v0.1.0-rc.2/install.ps1 | iex
Other options: --pre (newest release including pre-releases), --prefix DIR
($env:DEPSMITH_PREFIX), and --help.
Then depsmith init checks the native tools your targets use and offers to
install the missing ones. See
Getting started.
Quick start
depsmith discover --root path/to/project
depsmith check --root path/to/project --target pixi:pixi.toml
depsmith update --root path/to/project --target pixi:pixi.toml
check writes nothing and exits 1 when updates are pending. update shows
the changes and asks before applying. In CI, add --apply --yes --non-interactive --json
(CI integration).
from depsmith import UpdateOptions, prepare
proposal = prepare(
"path/to/project", targets=["pixi:pixi.toml"], options=UpdateOptions()
)
for change in proposal.changes:
print(change.diff)
if not proposal.failures:
proposal.apply()
Learn more
| Topic | Page |
|---|---|
Saved targets and options (depsmith.toml) |
Configuration |
| Proposals, stale inputs, partial apply, recovery | Reviewing and applying |
Pixi updates, upgrades, suggestions, --accept |
Pixi adapter |
| Actions release lines and commit pins | GitHub Actions adapter |
| Cargo lock owners, MSRV-aware updates | Cargo adapter |
| conda-lock environments, sharded repodata | Conda adapter |
| uv workspaces, Git pins, index evidence | uv adapter |
| npm workspaces, cooldowns, registry evidence | npm adapter |
| Grype scanning, identities, policy, suppressions | Vulnerability scanning |
| Common errors | Troubleshooting |
| Every command and option | CLI reference |
| The Python API | Python API |
The wiki is generated from docs/wiki/, and its terms follow the
glossary in CONTEXT.md.
Status
Alpha. The first release will be published to PyPI and as GitHub release binaries, with conda-forge after that (Releasing). Post-install project checks and interactive suggestion prompts are planned. New package managers plug in through one adapter module and a shared conformance suite (Architecture).
Contributing
See Development and testing
and Architecture.
Install the hooks with prek install --hook-type pre-commit --hook-type pre-push.
Changes land through pull requests with signed commits.
License
Metadata
Release files for depsmith 0.1.0rc2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| depsmith-0.1.0rc2.tar.gz | 213.6 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| depsmith-0.1.0rc2-cp310-abi3-win_amd64.whl | CPython 3.10 | abi3 | Windows x86-64 | Details |
| depsmith-0.1.0rc2-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.10 | abi3 | Linux glibc 2.17+ x86-64 | Details |
| depsmith-0.1.0rc2-cp310-abi3-macosx_11_0_arm64.whl | CPython 3.10 | abi3 | macOS 11.0+ ARM64 | Details |
| depsmith-0.1.0rc2-cp310-abi3-macosx_10_12_x86_64.whl | CPython 3.10 | abi3 | macOS 10.12+ x86-64 | Details |
Total release size: 17.7 MB
Release files / depsmith-0.1.0rc2.tar.gz
| Download URL | depsmith-0.1.0rc2.tar.gz |
|---|---|
| Size | 213.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
01116c680a1d3e76d964c4c36c37cbdc22d46d2856d1d79b7ced814c045a93e4
|
|
BLAKE2b-256 checksum How to use checksums |
1d1566943314cc4f547b20b69e9ba26515dc11e78394bcd55144dbc21d34438e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.
Transparency logRelease files / depsmith-0.1.0rc2-cp310-abi3-win_amd64.whl
| Download URL | depsmith-0.1.0rc2-cp310-abi3-win_amd64.whl |
|---|---|
| Size | 4.1 MB |
| Tags | CPython 3.10 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
d5c86aa5abfcc69d6b546db103bc70d59f1a5b548e92948235226c93b1aeb88f
|
|
BLAKE2b-256 checksum How to use checksums |
d8be7c62ff4f0665943ccd4c7fd708261722a7a15fd49fcff2673219605b0a48
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.
Transparency logRelease files / depsmith-0.1.0rc2-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | depsmith-0.1.0rc2-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 4.8 MB |
| Tags | CPython 3.10 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
30fe787000f37eff687c2726d547b0ad31048741a835f7ebe5715dc0fcd36de5
|
|
BLAKE2b-256 checksum How to use checksums |
b03b58426bd8a5472dfbd0f017896dd4e6c6093a77d460e569739b111b524ce6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.
Transparency logRelease files / depsmith-0.1.0rc2-cp310-abi3-macosx_11_0_arm64.whl
| Download URL | depsmith-0.1.0rc2-cp310-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 4.2 MB |
| Tags | CPython 3.10 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
508fd1a201dab1a85fafc153eaf08a4663dcfd85f8ff9d83e3ad18c6ccc6a939
|
|
BLAKE2b-256 checksum How to use checksums |
5c6c2c66ae38e88771bfb51c1815fcc06873bdc30c2d99168654ffe9adc3742d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.
Transparency logRelease files / depsmith-0.1.0rc2-cp310-abi3-macosx_10_12_x86_64.whl
| Download URL | depsmith-0.1.0rc2-cp310-abi3-macosx_10_12_x86_64.whl |
|---|---|
| Size | 4.4 MB |
| Tags | CPython 3.10 abi3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
50f4c2c344287148966fbc0b8e6dc5342496dc4a22d9bca2d3e721598daa941b
|
|
BLAKE2b-256 checksum How to use checksums |
1296d3993e9457f4b3f2f7cd8b270f1970d85ff7b75281842ed6880cdbb1d920
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.
Transparency log