This release is a pre-release and may not be stable for production use.
depsmith
Prepare, review and apply dependency updates for a repository, from a Rust CLI or a typed Python API. Each target is resolved by its own package manager in a disposable copy of the repository. You review the exact file and dependency changes, and the reviewed files are then written without resolving again.
- Supported: Pixi (
pixi.toml, Pixi-managedpyproject.toml), GitHub Actions workflow references, Cargo (Cargo.lockowners), conda (environment.ymllocked with conda-lock) and uv (pyproject.tomlwithuv.lock). - Safe by default: updates keep your constraints. Proposals go stale if the repository changes, and interrupted writes can be recovered.
- Evidence-backed suggestions for pins that block newer releases, which you can accept in the same declaration style.
- Optional vulnerability scanning compares before and after with one database snapshot. Packages it cannot assess are reported, never treated as clean.
📖 Documentation: the wiki
Install
python -m pip install . # from a checkout; Python 3.10+
depsmith init # checks the native tools your targets use; offers to install missing ones
A standalone executable builds with cargo build --release --locked -p depsmith-cli
(Rust 1.89+). See Getting started.
Quick start
depsmith discover --root path/to/project
depsmith check --root path/to/project --target pixi:pixi.toml
depsmith update --root path/to/project --target pixi:pixi.toml
check writes nothing and exits 1 when updates are pending. update shows
the changes and asks before applying. In CI, add --apply --yes --non-interactive --json
(CI integration).
from depsmith import UpdateOptions, prepare
proposal = prepare(
"path/to/project", targets=["pixi:pixi.toml"], options=UpdateOptions()
)
for change in proposal.changes:
print(change.diff)
if not proposal.failures:
proposal.apply()
Learn more
| Topic | Page |
|---|---|
Saved targets and options (depsmith.toml) |
Configuration |
| Proposals, stale inputs, partial apply, recovery | Reviewing and applying |
Pixi updates, upgrades, suggestions, --accept |
Pixi adapter |
| Actions release lines and commit pins | GitHub Actions adapter |
| Cargo lock owners, MSRV-aware updates | Cargo adapter |
| conda-lock environments, sharded repodata | Conda adapter |
| uv workspaces, Git pins, index evidence | uv adapter |
| Grype scanning, identities, policy, suppressions | Vulnerability scanning |
| Common errors | Troubleshooting |
| Every command and option | CLI reference |
| The Python API | Python API |
The wiki is generated from docs/wiki/, and its terms follow the
glossary in CONTEXT.md.
Status
Alpha. The first release will be published to PyPI and as GitHub release binaries, with conda-forge after that (Releasing). Post-install project checks and interactive suggestion prompts are planned. New package managers plug in through one adapter module and a shared conformance suite (Architecture).
Contributing
See Development and testing
and Architecture.
Install the hooks with prek install --hook-type pre-commit --hook-type pre-push.
Changes land through pull requests with signed commits.
License
Metadata
Release files for depsmith 0.1.0rc1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| depsmith-0.1.0rc1.tar.gz | 185.0 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| depsmith-0.1.0rc1-cp310-abi3-win_amd64.whl | CPython 3.10 | abi3 | Windows x86-64 | Details |
| depsmith-0.1.0rc1-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.10 | abi3 | Linux glibc 2.17+ x86-64 | Details |
| depsmith-0.1.0rc1-cp310-abi3-macosx_11_0_arm64.whl | CPython 3.10 | abi3 | macOS 11.0+ ARM64 | Details |
| depsmith-0.1.0rc1-cp310-abi3-macosx_10_12_x86_64.whl | CPython 3.10 | abi3 | macOS 10.12+ x86-64 | Details |
Total release size: 17.0 MB
Release files / depsmith-0.1.0rc1.tar.gz
| Download URL | depsmith-0.1.0rc1.tar.gz |
|---|---|
| Size | 185.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4ad4a7cd8646478b0ee49e08817f41deb4153a572709f21fb52820d27c932224
|
|
BLAKE2b-256 checksum How to use checksums |
1f69982bf5c50810104d681d0df8c47487bbe4232a6b3ef304e692bbb959f348
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / depsmith-0.1.0rc1-cp310-abi3-win_amd64.whl
| Download URL | depsmith-0.1.0rc1-cp310-abi3-win_amd64.whl |
|---|---|
| Size | 3.9 MB |
| Tags | CPython 3.10 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
9d6f91aa6ef991394af6839e7988adc4dc61a9bb6f28417efc833d619dad7db3
|
|
BLAKE2b-256 checksum How to use checksums |
714f208fa99db8c34301f61b0360da90885970cdf2f03f125903e1ae40ea1c9c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / depsmith-0.1.0rc1-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | depsmith-0.1.0rc1-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 4.6 MB |
| Tags | CPython 3.10 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
6ededc4d2c0f906debf7b346b9d2fc39ab6c357f6d2d7b82e6ae21b57b727dcc
|
|
BLAKE2b-256 checksum How to use checksums |
7daa3689a1c2db7200645848490e66b7d7b2503b2aa0341293b9ce582e1867ab
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / depsmith-0.1.0rc1-cp310-abi3-macosx_11_0_arm64.whl
| Download URL | depsmith-0.1.0rc1-cp310-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 4.1 MB |
| Tags | CPython 3.10 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
91ef2d1dd6783c8323b20807e4774889e6bed27d42e1df57ce3dc5d1c8d3c8c4
|
|
BLAKE2b-256 checksum How to use checksums |
74a54834fbdc9ba1de1d998f27def81fd086a8997bc677881906f7cc3f4913a8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / depsmith-0.1.0rc1-cp310-abi3-macosx_10_12_x86_64.whl
| Download URL | depsmith-0.1.0rc1-cp310-abi3-macosx_10_12_x86_64.whl |
|---|---|
| Size | 4.2 MB |
| Tags | CPython 3.10 abi3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
dd717120be7bb8726977da8f23bde5f5aed0dbd48f6e98e8ad0bf944888ab699
|
|
BLAKE2b-256 checksum How to use checksums |
89d7e59c07f4aaced8d9b653116dcbf58d9405145c1782ec42fd005569a60da8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log