Skip to main content

Codacy Badge Codacy Badge Documentation Status Build Code style: black GitHub Gitter Libraries.io dependency status for GitHub repo Maintenance GitHub issues PyPI - Python Version PyPI Contribute with Codespaces OpenSSF Best Practices

Vendor dependencies without the pain.

Dfetch copies source code directly into your project — no Git submodules, no SVN externals, no hidden external links. Fetch from Git, SVN, or plain archive URLs. Dependencies live as plain, readable files inside your own repository. You stay in full control of every line.

Dfetch supports Git, SVN, and archive files (.tar.gz, .tgz, .tar.bz2, .tar.xz, .zip). Archives can be verified with a cryptographic hash (sha256, sha384, or sha512) to guarantee integrity on every fetch. No proprietary formats, no lock-in — switch tools any time.

Other tools that do similar things are Zephyr's West, CMake ExternalProject, and other meta tools. See alternatives for a complete list. The broader concept is known as vendoring.

Getting started | Commands | Troubleshooting | Contributing

What Dfetch Does

  • Vendor source-only dependencies — fully self-contained, no external links at build time
  • VCS-agnostic: mix Git, SVN, and plain archive URLs freely in one manifest
  • Fetch and verify archives with cryptographic integrity checks
  • Apply local patches while keeping upstream syncable (dfetch diff / dfetch format-patch)
  • Supply-chain ready: SBOM generation, license detection, multi-format CI reports
  • Migrate from Git submodules or SVN externals in seconds (dfetch import)
  • Declarative code reuse across projects (inner sourcing)

Install

Stable

pip install dfetch

latest version

pip install git+https://github.com/dfetch-org/dfetch.git#egg=dfetch

Binary distributions

Each release on the releases page provides installers for all major platforms.

  • Linux .deb & .rpm
  • macOS .pkg
  • Windows .msi

Example manifest

manifest:
  version: 0.0

  remotes:                                                        # declare common sources in one place
  - name: github
    url-base: https://github.com/                                 # Allow git modules
    default: true                                                 # Set it as default

  - name: sourceforge
    url-base: svn://svn.code.sf.net/p/

  projects:

  - name: cpputest-git-tag
    dst: Tests/cpputest-git-tag
    url: https://github.com/cpputest/cpputest.git                 # Use external git directly
    tag: v3.4                                                     # revision can also be a tag

  - name: tortoise-svn-branch-rev
    dst: Tests/tortoise-svn-branch-rev/
    remote: sourceforge
    branch: 1.10.x
    revision: '28553'
    src: src/*
    vcs: svn
    repo-path: tortoisesvn/code

  - name: tortoise-svn-tag
    dst: Tests/tortoise-svn-tag/
    remote: sourceforge
    tag: version-1.13.1
    src: src/*.txt
    vcs: svn
    repo-path: tortoisesvn/code

  - name: cpputest-git-src
    dst: Tests/cpputest-git-src
    repo-path: cpputest/cpputest.git
    src: src

  - name: my-library
    dst: ext/my-library
    url: https://example.com/releases/my-library-1.0.tar.gz
    vcs: archive
    integrity:
      hash: sha256:e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

GitHub Action

You can use Dfetch in your GitHub Actions workflow to check your dependencies. The results will be uploaded to GitHub. Add the following to your workflow file:

jobs:
  dfetch-check:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      security-events: write
    steps:
      - name: Run Dfetch Check
        uses: dfetch-org/dfetch@main
        with:
          working-directory: '.' # optional, defaults to project root

Release files for dfetch 0.14.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dfetch 0.14.4
File Size Uploaded
dfetch-0.14.4.tar.gz 5.6 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for dfetch 0.14.4
File Interpreter ABI Platform
dfetch-0.14.4-py3-none-any.whl Python 3 none any Details

Total release size: 5.8 MB

Release files / dfetch-0.14.4.tar.gz

Download URL dfetch-0.14.4.tar.gz
Size 5.6 MB
Tags Source
SHA-256 checksum
How to use checksums
3b99cee230be818bd809d230e61f5f47422a484119456f01ebdad861a06df8a7
BLAKE2b-256 checksum
How to use checksums
a1d4545c04b208cea0f0d11fc6417fdbd9dae7cc0705848a2fef2abbdde9282d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release files / dfetch-0.14.4-py3-none-any.whl

Download URL dfetch-0.14.4-py3-none-any.whl
Size 157.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3f35210a0c6502267789fa20c6c61aed23ed967d40e726a6fbfd1b3f2015a9a2
BLAKE2b-256 checksum
How to use checksums
fc2ab6fc4d3315ea68e38059836964d4b1f789cd5da7571a145520d6d5bc8922
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.14.4 This release

2 release files

0.14.3

2 release files

0.14.2

2 release files

0.14.1

2 release files

0.14.0

2 release files

0.13.0

2 release files

0.12.1

2 release files

0.12.0

2 release files

0.10.0

2 release files

0.9.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

0.0.9

2 release files

0.0.8

2 release files

0.0.7

2 release files

0.0.6

2 release files

0.0.5

2 release files

0.0.4

2 release files

0.0.3

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page