nab
nab is an experimental Python packaging lock and package download tool, aiming to have similar resolver performance to uv, while being written in Python.
nab reads a pyproject.toml, resolves the dependency tree, and
writes a pinned set of versions or a PEP 751 lockfile. It does not
install. Hand the lockfile to whatever installer you trust.
Documentation
Install
For package hygiene, and security reasons, the preference is to install nab itself as a tool, e.g.
Via pipx:
pipx install nab
Or via uv:
uv tool install nab
Quick start
# pyproject.toml
[project]
name = "example"
version = "0.1.0"
dependencies = [
"starlette<=0.36.0",
"fastapi<=0.115.2",
]
nab lock pyproject.toml
Writes pylock.toml next to the project. For a pip-style
requirements list instead, use
nab lock --format requirements-without-hashes --output -.
Security
nab makes some opinionated choices to be secure first
Build policy
By default nab tries to extract static metadata, even from sdists, but sometimes that is not possible and you have to build a package to extract the dependency metadata. There are three build policies:
- never: Never builds a Python package
- build-local (default): Builds
[[tool.nab.local-sources]]entries and workspace members when theirpyproject.tomlcannot be read statically - build-remote: Also builds
[[tool.nab.vcs-sources]]clones,[[tool.nab.archive-sources]]trees, and sdists from an index. It is recommended that this only be turned on via per-package override
Indexes
nab does not currently support sourcing the same package from distinct indexes. Indexes are processed in the order they are given to nab, and the first index that has a package is the only index that nab will source that package.
You can override this behavior by pinning specific packages to specific behavior.
You can also list different urls as a mirror for the same index. When a lockfile is written the primary url will always be used so that the lockfile will be stable, even if mirrors are used (this feature is a work in progress).
VCS policy
By default nab refuses every git URL, pinned or not:
[tool.nab.vcs]
policy = "block"
allowed-schemes = []
allowed-repos = []
require-pin = true
Each of the first three refuses everything until you set it:
policy: set toallowto consider git URLs at allallowed-schemes: the schemes you accept, e.g.git+httpsallowed-repos: the repository prefixes you accept, e.g.https://github.com/myorg/
require-pin is on by default, so a URL has to carry a
40-character commit hash and a floating branch or tag is
refused.
A package is then taken from a repository through a
[[tool.nab.vcs-sources]] entry. A pkg @ git+... requirement
under [project].dependencies gets the same admission checks,
but nab cannot resolve that form yet, so use a source entry.
Standards first behavior
Pre-releases
Pre-release versions are selected if there are no stable versions to select given the requirements, even for transitive dependencies. A user option to force allow or block pre-releases per-package is a work in progress.
Validate per-distribution dependencies
By default when a distribution is chosen the dependencies from that distribution are used, nab does not assume two different distributions for the same package version will have the same dependencies.
However, sometimes you may want the lock file to produce an sdist, that sdist may not have static metadata, and you don't want to wait for the sdist to build on every lock, there is a distribution policy of "sdist-install", that is the metadata will be taken from an appropriate wheel, but the sdist will be selected for the install.
Libraries
This project includes multiple libraries that can be used by other tools:
nab-resolver: An agnostic resolver library based on PubGrub, but with extensions that make it compatible with Python packaging standardsnab-markersets: The PEP 508 marker algebra, reading a marker as the set of environments it selects so markers can be combined and comparednab-provider: The Python packaging provider that drives the nab-resolver, with lots of specific features and optimizations for the Python packaging ecosystem. It does no I/O: everything comes through one interface a host implementsnab-index: Provides APIs for talking to Python package indexes, abstracts HTTP library interface so different HTTP libraries can be plugged innab-project: nab's own host. It implements the fetch interface over nab-index and adds the resolve orchestration, workspace discovery, the build path, the lockfile emitter and the downloader
All 5 libraries are in experimental mode, I currently recommend pinning them,
e.g. nab-resolver==0.0.1, as APIs may change at any point.
Once we reach 0.1.0 we will only break API stability on each minor update,
so you will be able to pin to ==0.1.* or ~=0.1.0.
Metadata
Release files for nab 0.0.16
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| nab-0.0.16.tar.gz | 258.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| nab-0.0.16-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 388.8 kB
Release files / nab-0.0.16.tar.gz
| Download URL | nab-0.0.16.tar.gz |
|---|---|
| Size | 258.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
49a5c9ef8edeb6cc283e5e6cf662e8ff52ce23a3217ceecee3d0ee44549ff49c
|
|
BLAKE2b-256 checksum How to use checksums |
45c0d985c2fa4d46ade9539efa84faeeea7501286450a0b843b736cf4b1fff3b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.
Transparency logRelease files / nab-0.0.16-py3-none-any.whl
| Download URL | nab-0.0.16-py3-none-any.whl |
|---|---|
| Size | 130.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a9ef18b9c1d7ae36520c1b4c5e7754c0d92e8a77de0093ba9f77592ef62cd06b
|
|
BLAKE2b-256 checksum How to use checksums |
59c00e130eccf0e6f5ee9e8f9a0ac09bb5d19c81691ceabe052596c45a794567
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.
Transparency log