Skip to main content

depvex

depvex generates and checks requirements.txt files from static Python imports. It is designed for a single Python application and for repositories that contain multiple independently managed services.

Core capabilities

  • AST-based detection of import and from ... import ... statements.
  • Standard-library filtering and per-import opt-out with # ignore depvex.
  • Recursive Python-file discovery with built-in ignored directories and YAML ignore_dirs and ignore_packages support.
  • Import-module to installed-distribution mapping through importlib.metadata.
  • Version lookup from installed metadata without subprocesses, followed by an optional PyPI fallback.
  • Existing dependency pins are retained when the package remains in use; stale entries are removed during a scan.
  • One-time scan, CI-oriented check, and debounced filesystem watch mode.
  • Per-service requirements files plus a root requirements file for microservice repositories.
  • Detailed check output for missing, stale, and changed entries.
  • Optional [project].dependencies sync/check and service dependency reports.

Install

Requires Python 3.11+.

python -m pip install depvex

Install PyYAML separately to enable depvex.yaml or depvex.yml:

python -m pip install PyYAML

Intended command interface

depvex --scan .
depvex --check .
depvex --watch .
depvex --report .
  • --scan updates requirements files.
  • --check returns exit code 0 when requirements files match the detected imports and 1 otherwise.
  • --watch performs an initial scan and updates files after created or modified Python-file events.
  • --report prints dependencies per service and shared dependencies without changing files.

Use --pyproject with --scan to write, or with --check to verify, [project].dependencies in an existing pyproject.toml.

Version note

The new source interface above is not compatible with older published releases, which use positional commands such as depvex check .. Install and invoke one version consistently in CI.

Single application

Without configured services, scanning a directory creates or updates its single requirements.txt:

depvex --scan ./my-app

Microservices

Define direct child service folders in depvex.yaml:

micro_servi_folders:
  - api
  - worker

ignore_dirs:
  - tests

ignore_packages:
  - pytest
  - depvex

Scanning the repository produces:

repository/
├── api/requirements.txt
├── worker/requirements.txt
└── requirements.txt

The root file covers Python files outside api and worker; service-only imports are excluded from it. Watch mode rescans only the affected service when a file changes below a configured service folder.

The current key spelling is micro_servi_folders, and service configuration is read from YAML only. config.json is used for CAPTIVE_PORTAL_URLS and debounce_seconds, not service discovery.

CI

Install the target project's dependencies and the checked-out project before checking, so package metadata is available and the local code is executed:

- run: |
    python -m pip install -r requirements.txt
    python -m pip install .
- run: depvex --check .

check reports missing, stale, and changed dependency entries. Run scan, review the resulting diff, and commit expected changes.

Scope and roadmap

Depvex does not resolve dynamic imports or replace a lockfile manager. Future work includes a canonical microservice configuration key and broader automated coverage for single-project, microservice, watch, and CI scenarios.

Metadata

Release files for depvex 0.1.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for depvex 0.1.7
File Size Uploaded
depvex-0.1.7.tar.gz 369.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for depvex 0.1.7
File Interpreter ABI Platform
depvex-0.1.7-py3-none-any.whl Python 3 none any Details

Total release size: 555.9 kB

Release files / depvex-0.1.7.tar.gz

Download URL depvex-0.1.7.tar.gz
Size 369.8 kB
Tags Source
SHA-256 checksum
How to use checksums
eca5a402155c30b33f5a3647978bf0d8528fe8c4b048a94895593b51404988f4
BLAKE2b-256 checksum
How to use checksums
47438a3bfe56ff367ecd6a095aded2ad17fc83c8574756edee660615eded79cf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release files / depvex-0.1.7-py3-none-any.whl

Download URL depvex-0.1.7-py3-none-any.whl
Size 186.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
468018e8cfbe535c1759e88129189c805f0112ed4a0a4a0e753a3dc0dfb118d3
BLAKE2b-256 checksum
How to use checksums
3104dcd6d6263e497964fa4f3135340fd9a3594823e25846ae4004c1c7e5df1b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release history Release notifications | RSS feed

0.1.10

2 release files

0.1.9

2 release files

0.1.8

2 release files

This release

0.1.7 This release

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page