Skip to main content

depvex

depvex generates and checks requirements.txt files from static Python imports. It is designed for a single Python application and for repositories that contain multiple independently managed services.

Core capabilities

  • AST-based detection of import and from ... import ... statements.
  • Standard-library filtering and per-import opt-out with # ignore depvex.
  • Skips imports inside if TYPE_CHECKING: blocks to avoid adding type-only imports.
  • Recursive Python-file discovery with built-in ignored directories and YAML ignore_dirs and ignore_packages support.
  • Import-module to installed-distribution mapping through importlib.metadata.
  • Version lookup from installed metadata without subprocesses, followed by an optional PyPI fallback.
  • Existing dependency pins are retained when the package remains in use; stale entries are removed during a scan.
  • One-time scan, CI-oriented check, and debounced filesystem watch mode.
  • Per-service requirements files plus a root requirements file for microservice repositories.
  • Detailed check output for missing, stale, and changed entries.
  • Optional [project].dependencies sync/check and service dependency reports.

Install

Requires Python 3.11+.

python -m pip install depvex

Install PyYAML separately to enable depvex.yaml or depvex.yml:

python -m pip install PyYAML

Intended command interface

depvex --scan .
depvex --check .
depvex --watch .
depvex --report .
  • --scan updates requirements files.
  • --check returns exit code 0 when requirements files match the detected imports and 1 otherwise.
  • --watch performs an initial scan and updates files after created or modified Python-file events.
  • --report prints dependencies per service and shared dependencies without changing files.

Use --pyproject with --scan to write, or with --check to verify, [project].dependencies in an existing pyproject.toml.

Version note

The new source interface above is not compatible with older published releases, which use positional commands such as depvex check .. Install and invoke one version consistently in CI.

Single application

Without configured services, scanning a directory creates or updates its single requirements.txt:

depvex --scan ./my-app

Microservices

Define direct child service folders in depvex.yaml:

micro_servi_folders:
  - api
  - worker

ignore_dirs:
  - tests

ignore_packages:
  - pytest
  - depvex

Scanning the repository produces:

repository/
├── api/requirements.txt
├── worker/requirements.txt
└── requirements.txt

The root file covers Python files outside api and worker; service-only imports are excluded from it. Watch mode rescans only the affected service when a file changes below a configured service folder.

The current key spelling is micro_servi_folders, and service configuration is read from YAML only. config.json is used for CAPTIVE_PORTAL_URLS and debounce_seconds, not service discovery.

CI

Install the target project's dependencies and the checked-out project before checking, so package metadata is available and the local code is executed:

- run: |
    python -m pip install -r requirements.txt
    python -m pip install .
- run: depvex --check .

check reports missing, stale, and changed dependency entries. Run scan, review the resulting diff, and commit expected changes.

Scope and roadmap

Depvex does not resolve dynamic imports or replace a lockfile manager. Future work includes a canonical microservice configuration key and broader automated coverage for single-project, microservice, watch, and CI scenarios.

Metadata

Release files for depvex 0.1.8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for depvex 0.1.8
File Size Uploaded
depvex-0.1.8.tar.gz 370.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for depvex 0.1.8
File Interpreter ABI Platform
depvex-0.1.8-py3-none-any.whl Python 3 none any Details

Total release size: 557.0 kB

Release files / depvex-0.1.8.tar.gz

Download URL depvex-0.1.8.tar.gz
Size 370.6 kB
Tags Source
SHA-256 checksum
How to use checksums
00069539a2a3992eef5876d1f992652dcbd06f95c99afdd244f54eb4c08c92f7
BLAKE2b-256 checksum
How to use checksums
099fc5209859ef8e4a0007021bdcfd66370d7be71bdc5e3d5a7db98d0d7e5893
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release files / depvex-0.1.8-py3-none-any.whl

Download URL depvex-0.1.8-py3-none-any.whl
Size 186.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5a5b6d654448d187438034d34c4925bbc1dfdc4b77d4e4850bcc6bcfea58efb9
BLAKE2b-256 checksum
How to use checksums
d6d9bf9c97e5325d7e5a6017f959117ac2b80772105b916c786bab542e4f4636
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release history Release notifications | RSS feed

0.1.10

2 release files

0.1.9

2 release files

This release

0.1.8 This release

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page