Skip to main content

It-Depends

Unit tests Integration tests PyPI version Slack Status

It-Depends is a tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories. It supports Go, JavaScript, Rust, Python, C/C++ (cmake and autotools), and Ubuntu packages.

What makes it different from similar tools:

  • Resolves all possible dependency versions, not just a single feasible resolution
  • C/C++ support via cmake and autotools without building the project
  • Automated native library dependency mapping via dynamic analysis (e.g., pytz depends on libtinfo.so.6)
  • Vulnerability scanning against the OSV database
  • Dependency similarity comparison between packages

Installation

pip3 install it-depends

Ecosystem-specific tools must be installed separately: npm for JavaScript, cargo for Rust, pip for Python, autotools/cmake for C/C++. Native dependency resolution and Ubuntu package analysis require a Docker-compatible container runtime with an accessible socket (e.g., Docker Desktop, Podman, or Colima).

Usage

it-depends .                        # Analyze current directory
it-depends . --list                 # List compatible resolvers
it-depends /path/to/project         # Analyze a different repository

it-depends "pip:numpy"              # Analyze a pip package
it-depends "ubuntu:libc6@2.35"      # Analyze a Ubuntu package
it-depends "npm:lodash@>=4.17.0"    # Specify a version constraint

it-depends --audit "pip:numpy"                          # Include vulnerability audit
it-depends --depth-limit 1 "pip:scikit-learn"           # Only direct dependencies
it-depends --output-format dot --output-file file.dot . # Output as Graphviz/Dot

Development

git clone https://github.com/trailofbits/it-depends
cd it-depends
make sync
uv run it-depends --help
make format lint integration

Acknowledgements

This research was developed by Trail of Bits based upon work supported by DARPA under Contract No. HR001120C0084 (Distribution Statement A, Approved for Public Release: Distribution Unlimited). Any opinions, findings and conclusions or recommendations expressed in this material are those of the author(s) and do not necessarily reflect the views of the United States Government or DARPA.

Evan Sultanik and Evan Downing are the active maintainers. Felipe Manzano, Alessandro Gario, Eric Kilmer, Alexander Remie, and Henrik Brodin all made significant contributions to the tool's inception and development.

Metadata

Release files for it-depends 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for it-depends 0.2.1
File Size Uploaded
it_depends-0.2.1.tar.gz 88.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for it-depends 0.2.1
File Interpreter ABI Platform
it_depends-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 171.4 kB

Release files / it_depends-0.2.1.tar.gz

Download URL it_depends-0.2.1.tar.gz
Size 88.4 kB
Tags Source
SHA-256 checksum
How to use checksums
0ce3d5317f1d72dd802c437791a92b6ee6d45f6d675a2c3176622536fa400563
BLAKE2b-256 checksum
How to use checksums
2d18d951f58ec9664f21bda0d882a71f49373fe083665af6280fabf1462d0f06
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.

Transparency log

Release files / it_depends-0.2.1-py3-none-any.whl

Download URL it_depends-0.2.1-py3-none-any.whl
Size 83.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7d00c16a47cb8b2c3119a1645029ef37703d4fbf388f6a714fcd8e30611b483b
BLAKE2b-256 checksum
How to use checksums
ae0c5f31a54fb7fb30c0a450d596c1675eab81db642aedf853faea4cda6a504c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page