Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

depsmith

CI Coverage License: MIT

Prepare, review and apply dependency updates for a repository, from a Rust CLI or a typed Python API. Each target is resolved by its own package manager in a disposable copy of the repository. You review the exact file and dependency changes, and the reviewed files are then written without resolving again.

  • Supported: Pixi (pixi.toml, Pixi-managed pyproject.toml), GitHub Actions workflow references, Cargo (Cargo.lock owners), conda (environment.yml locked with conda-lock) and uv (pyproject.toml with uv.lock).
  • Safe by default: updates keep your constraints. Proposals go stale if the repository changes, and interrupted writes can be recovered.
  • Evidence-backed suggestions for pins that block newer releases, which you can accept in the same declaration style.
  • Optional vulnerability scanning compares before and after with one database snapshot. Packages it cannot assess are reported, never treated as clean.

📖 Documentation: the wiki

Install

python -m pip install .   # from a checkout; Python 3.10+
depsmith init             # checks the native tools your targets use; offers to install missing ones

A standalone executable builds with cargo build --release --locked -p depsmith-cli (Rust 1.89+). See Getting started.

Quick start

depsmith discover --root path/to/project
depsmith check    --root path/to/project --target pixi:pixi.toml
depsmith update   --root path/to/project --target pixi:pixi.toml

check writes nothing and exits 1 when updates are pending. update shows the changes and asks before applying. In CI, add --apply --yes --non-interactive --json (CI integration).

from depsmith import UpdateOptions, prepare

proposal = prepare(
    "path/to/project", targets=["pixi:pixi.toml"], options=UpdateOptions()
)
for change in proposal.changes:
    print(change.diff)
if not proposal.failures:
    proposal.apply()

Learn more

Topic Page
Saved targets and options (depsmith.toml) Configuration
Proposals, stale inputs, partial apply, recovery Reviewing and applying
Pixi updates, upgrades, suggestions, --accept Pixi adapter
Actions release lines and commit pins GitHub Actions adapter
Cargo lock owners, MSRV-aware updates Cargo adapter
conda-lock environments, sharded repodata Conda adapter
uv workspaces, Git pins, index evidence uv adapter
Grype scanning, identities, policy, suppressions Vulnerability scanning
Common errors Troubleshooting
Every command and option CLI reference
The Python API Python API

The wiki is generated from docs/wiki/, and its terms follow the glossary in CONTEXT.md.

Status

Alpha. The first release will be published to PyPI and as GitHub release binaries, with conda-forge after that (Releasing). Post-install project checks and interactive suggestion prompts are planned. New package managers plug in through one adapter module and a shared conformance suite (Architecture).

Contributing

See Development and testing and Architecture. Install the hooks with prek install --hook-type pre-commit --hook-type pre-push. Changes land through pull requests with signed commits.

License

MIT

Metadata

Release files for depsmith 0.1.0rc1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for depsmith 0.1.0rc1
File Size Uploaded
depsmith-0.1.0rc1.tar.gz 185.0 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for depsmith 0.1.0rc1
File
depsmith-0.1.0rc1-cp310-abi3-win_amd64.whl CPython 3.10 abi3 Windows x86-64 Details
depsmith-0.1.0rc1-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.10 abi3 Linux glibc 2.17+ x86-64 Details
depsmith-0.1.0rc1-cp310-abi3-macosx_11_0_arm64.whl CPython 3.10 abi3 macOS 11.0+ ARM64 Details
depsmith-0.1.0rc1-cp310-abi3-macosx_10_12_x86_64.whl CPython 3.10 abi3 macOS 10.12+ x86-64 Details

Total release size: 17.0 MB

Release files / depsmith-0.1.0rc1.tar.gz

Download URL depsmith-0.1.0rc1.tar.gz
Size 185.0 kB
Tags Source
SHA-256 checksum
How to use checksums
4ad4a7cd8646478b0ee49e08817f41deb4153a572709f21fb52820d27c932224
BLAKE2b-256 checksum
How to use checksums
1f69982bf5c50810104d681d0df8c47487bbe4232a6b3ef304e692bbb959f348
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / depsmith-0.1.0rc1-cp310-abi3-win_amd64.whl

Download URL depsmith-0.1.0rc1-cp310-abi3-win_amd64.whl
Size 3.9 MB
Tags CPython 3.10 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
9d6f91aa6ef991394af6839e7988adc4dc61a9bb6f28417efc833d619dad7db3
BLAKE2b-256 checksum
How to use checksums
714f208fa99db8c34301f61b0360da90885970cdf2f03f125903e1ae40ea1c9c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / depsmith-0.1.0rc1-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL depsmith-0.1.0rc1-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 4.6 MB
Tags CPython 3.10 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
6ededc4d2c0f906debf7b346b9d2fc39ab6c357f6d2d7b82e6ae21b57b727dcc
BLAKE2b-256 checksum
How to use checksums
7daa3689a1c2db7200645848490e66b7d7b2503b2aa0341293b9ce582e1867ab
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / depsmith-0.1.0rc1-cp310-abi3-macosx_11_0_arm64.whl

Download URL depsmith-0.1.0rc1-cp310-abi3-macosx_11_0_arm64.whl
Size 4.1 MB
Tags CPython 3.10 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
91ef2d1dd6783c8323b20807e4774889e6bed27d42e1df57ce3dc5d1c8d3c8c4
BLAKE2b-256 checksum
How to use checksums
74a54834fbdc9ba1de1d998f27def81fd086a8997bc677881906f7cc3f4913a8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / depsmith-0.1.0rc1-cp310-abi3-macosx_10_12_x86_64.whl

Download URL depsmith-0.1.0rc1-cp310-abi3-macosx_10_12_x86_64.whl
Size 4.2 MB
Tags CPython 3.10 abi3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
dd717120be7bb8726977da8f23bde5f5aed0dbd48f6e98e8ad0bf944888ab699
BLAKE2b-256 checksum
How to use checksums
89d7e59c07f4aaced8d9b653116dcbf58d9405145c1782ec42fd005569a60da8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0rc1 This release

5 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page