Skip to main content

depvex

depvex generates and checks requirements.txt files from static Python imports. It is designed for a single Python application and for repositories that contain multiple independently managed services.

Core capabilities

  • AST-based detection of import and from ... import ... statements.
  • Standard-library filtering and per-import opt-out with # ignore depvex.
  • Skips imports inside if TYPE_CHECKING: blocks to avoid adding type-only imports.
  • Recursive discovery across .py and Jupyter Notebook (.ipynb) files.
  • Automatically isolates notebook dependencies into requirements-notebooks.txt (or merges into requirements.txt via notebooks_target).
  • Built-in directory exclusions plus YAML ignore_dirs and ignore_packages support.
  • Import-module to installed-distribution mapping through importlib.metadata.
  • Version lookup from installed metadata without subprocesses, followed by an optional PyPI fallback.
  • Existing dependency pins are retained when the package remains in use; stale entries are removed during a scan.
  • One-time scan, CI-oriented check, and debounced filesystem watch mode.
  • Per-service requirements files plus a root requirements file for microservice repositories.
  • Detailed check output for missing, stale, and changed entries.
  • Optional [project].dependencies sync/check and service dependency reports.

Install

Requires Python 3.11+.

python -m pip install depvex

Install PyYAML separately to enable depvex.yaml or depvex.yml:

python -m pip install PyYAML

Intended command interface

depvex --scan .
depvex --check .
depvex --watch .
depvex --report .
  • --scan updates requirements files.
  • --check returns exit code 0 when requirements files match the detected imports and 1 otherwise.
  • --watch performs an initial scan and updates files after created or modified Python-file events.
  • --report prints dependencies per service and shared dependencies without changing files.
  • Multiple commands can be selected together, for example depvex --scan --check --report .; they run sequentially by default.
  • Use --parallel and optionally --jobs N to run one command concurrently across independent project paths, for example depvex --parallel --scan ./service-a ./service-b. Use --continue-on-error to continue sequential execution after a failed command.
  • Do not combine --parallel with multiple commands on the same path; commands such as scan and check depend on one another and must run sequentially.
  • Use --ignore-dir DIR to add a directory exclusion from the CLI. Repeat the option for multiple directories; CLI exclusions are combined with YAML ignore_dirs values.
  • --watch cannot be combined with other commands because it is long-running.

Use --pyproject with --scan to write, or with --check to verify, [project].dependencies in an existing pyproject.toml.

Version note

The new source interface above is not compatible with older published releases, which use positional commands such as depvex check .. Install and invoke one version consistently in CI.

Single application

Without configured services, scanning a directory creates or updates its single requirements.txt:

depvex --scan ./my-app

Microservices

Define direct child service folders in depvex.yaml:

micro_servi_folders:
  - api
  - worker

ignore_dirs:
  - tests

ignore_packages:
  - pytest
  - depvex

Scanning the repository produces:

repository/
├── api/requirements.txt
├── worker/requirements.txt
└── requirements.txt

The root file covers Python files outside api and worker; service-only imports are excluded from it. Watch mode rescans only the affected service when a file changes below a configured service folder.

The current key spelling is micro_servi_folders, and service configuration is read from YAML only. config.json is used for CAPTIVE_PORTAL_URLS and debounce_seconds, not service discovery.

CI

Install the target project's dependencies and the checked-out project before checking, so package metadata is available and the local code is executed:

- run: |
    python -m pip install -r requirements.txt
    python -m pip install .
- run: depvex --check .

check reports missing, stale, and changed dependency entries. Run scan, review the resulting diff, and commit expected changes.

Scope and roadmap

Depvex does not resolve dynamic imports or replace a lockfile manager. Future work includes a canonical microservice configuration key and broader automated coverage for single-project, microservice, watch, and CI scenarios.

Metadata

Release files for depvex 0.1.10

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for depvex 0.1.10
File Size Uploaded
depvex-0.1.10.tar.gz 353.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for depvex 0.1.10
File Interpreter ABI Platform
depvex-0.1.10-py3-none-any.whl Python 3 none any Details

Total release size: 510.7 kB

Release files / depvex-0.1.10.tar.gz

Download URL depvex-0.1.10.tar.gz
Size 353.9 kB
Tags Source
SHA-256 checksum
How to use checksums
ed5a444ae50aad89e3cd8d58a353a6a83993889d00fefbaca602bd00f7c3ffac
BLAKE2b-256 checksum
How to use checksums
7d6302f9a681f4f33d02eda1889b89ac65c3aa18fdac619a4dc013f4b93c3d16
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release files / depvex-0.1.10-py3-none-any.whl

Download URL depvex-0.1.10-py3-none-any.whl
Size 156.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
34b385f751abc714422f78815e1f937cd1019bd07f6df7a301e0e8338fdb57a5
BLAKE2b-256 checksum
How to use checksums
cc521c2389169b9d9bb5a5e97f3c03e1a547d7e4dd4f7238aad703ff48520b1b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release history Release notifications | RSS feed

This release

0.1.10 This release

2 release files

0.1.9

2 release files

0.1.8

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page