It-Depends
It-Depends is a tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories. It supports Go, JavaScript, Rust, Python, C/C++ (cmake and autotools), and Ubuntu packages.
What makes it different from similar tools:
- Resolves all possible dependency versions, not just a single feasible resolution
- C/C++ support via cmake and autotools without building the project
- Automated native library dependency mapping via dynamic analysis (e.g.,
pytzdepends onlibtinfo.so.6) - Vulnerability scanning against the OSV database
- Dependency similarity comparison between packages
Installation
pip3 install it-depends
Ecosystem-specific tools must be installed separately: npm for JavaScript, cargo for Rust, pip for Python, autotools/cmake for C/C++. Native dependency resolution and Ubuntu package analysis require a Docker-compatible container runtime with an accessible socket (e.g., Docker Desktop, Podman, or Colima).
Usage
it-depends . # Analyze current directory
it-depends . --list # List compatible resolvers
it-depends /path/to/project # Analyze a different repository
it-depends "pip:numpy" # Analyze a pip package
it-depends "ubuntu:libc6@2.35" # Analyze a Ubuntu package
it-depends "npm:lodash@>=4.17.0" # Specify a version constraint
it-depends --audit "pip:numpy" # Include vulnerability audit
it-depends --depth-limit 1 "pip:scikit-learn" # Only direct dependencies
it-depends --output-format dot --output-file file.dot . # Output as Graphviz/Dot
Development
git clone https://github.com/trailofbits/it-depends
cd it-depends
make sync
uv run it-depends --help
make format lint integration
Acknowledgements
This research was developed by Trail of Bits based upon work supported by DARPA under Contract No. HR001120C0084 (Distribution Statement A, Approved for Public Release: Distribution Unlimited). Any opinions, findings and conclusions or recommendations expressed in this material are those of the author(s) and do not necessarily reflect the views of the United States Government or DARPA.
Evan Sultanik and Evan Downing are the active maintainers. Felipe Manzano, Alessandro Gario, Eric Kilmer, Alexander Remie, and Henrik Brodin all made significant contributions to the tool's inception and development.
Metadata
Release files for it-depends 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| it_depends-0.2.1.tar.gz | 88.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| it_depends-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 171.4 kB
Release files / it_depends-0.2.1.tar.gz
| Download URL | it_depends-0.2.1.tar.gz |
|---|---|
| Size | 88.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0ce3d5317f1d72dd802c437791a92b6ee6d45f6d675a2c3176622536fa400563
|
|
BLAKE2b-256 checksum How to use checksums |
2d18d951f58ec9664f21bda0d882a71f49373fe083665af6280fabf1462d0f06
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.
Transparency logRelease files / it_depends-0.2.1-py3-none-any.whl
| Download URL | it_depends-0.2.1-py3-none-any.whl |
|---|---|
| Size | 83.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7d00c16a47cb8b2c3119a1645029ef37703d4fbf388f6a714fcd8e30611b483b
|
|
BLAKE2b-256 checksum How to use checksums |
ae0c5f31a54fb7fb30c0a450d596c1675eab81db642aedf853faea4cda6a504c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.
Transparency log