PyDependencyCheck
Dependency intelligence and supply-chain security for Python projects. A Rust core (dependency parsing, graph algorithms, OSV vulnerability scanning) wrapped in a Python CLI: scan dependencies, see who introduced them and why, find unused packages, check license compliance, generate signed SBOMs, and gate CI builds on a real health score.
What it does
- Scan: auto-detect and parse
requirements.txt,pyproject.toml(PEP 621 and Poetry), andconstraints.txt, handling every PEP 508 version operator and extras. - Why / trace: git-blame-based provenance (who added a dependency, in which commit) and full chronological history across the project's git log.
- Health: a real, computed 0-100 score combining live OSV.dev vulnerability data, PyPI release staleness, AST-detected dead dependencies, and dependency-graph complexity.
- SBOM export: CycloneDX 1.4 and SPDX 2.3 JSON, with optional RSA-SHA256 signing and verification.
- License compliance: fetches real PyPI license metadata, classifies permissive/copyleft/restricted, and checks compatibility against your project's own license.
- CI gating:
gatecomputes the same health score and exits non-zero on failure, with GitHub Actions::error/::warning/::noticeannotations when run inside a GitHub Actions job. - Drift & history: SQLite-backed snapshots so you can diff what changed since a baseline.
- OpenTelemetry: optional tracing/metrics via
--otel, defaulting to a console exporter (no collector required) or OTLP/Jaeger/Prometheus if configured.
Installation
pip install pydependencycheck
For SBOM signing (needs cryptography) or OpenTelemetry export:
pip install "pydependencycheck[sbom,otel]"
Requires Python 3.8+. Prebuilt wheels are published for Linux, macOS (Intel/Apple Silicon), and Windows; see .github/INSTALL.md if you need to build from source.
Quick start
# Scan the current project
pydependencycheck scan .
# Why is this package installed, and who added it?
pydependencycheck why requests
# Full git history for a dependency (added/upgraded/downgraded over time)
pydependencycheck trace requests
# Real health score: live vulnerabilities, staleness, dead deps, complexity
pydependencycheck health
# License compliance report, checked against your project's license
pydependencycheck licenses --project-license MIT
# Export a signed CycloneDX SBOM
pydependencycheck export --format cyclonedx --output sbom.json
# Gate a CI build: exits non-zero if health/vulnerabilities/dead-deps fail thresholds
pydependencycheck gate --min-health 50
Commands
| Command | What it does |
|---|---|
scan |
Parse dependency files, report direct/transitive counts (table, JSON, HTML, or Markdown) |
list |
Table of all detected dependencies |
why PACKAGE |
Git-blame provenance: who added it, in which commit |
trace PACKAGE |
Current status plus full git history for that dependency |
health |
Computed health score (vulnerabilities, staleness, dead deps, complexity) |
licenses |
License classification + compatibility check per dependency |
export |
SBOM export (CycloneDX or SPDX), optionally signed |
gate |
CI gate: real exit code based on health/vulnerability/dead-dep thresholds |
snapshot |
Save or inspect a dependency snapshot |
history |
Timeline of saved snapshots |
drift |
Diff the current scan against a saved baseline |
Run pydependencycheck COMMAND --help for the full option list on any command (most support --path, and scan/export/licenses/health/gate support --offline/--path variants where relevant).
Health scoring
health (and gate) combine four real, independently-computed factors:
pydependencycheck health
Dependency Health Score: 87/100 (Excellent)
Health Score Breakdown
┏━━━━━━━━━━━━━━━━━┳━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━┓
┃ Factor ┃ Score ┃ Status ┃
┡━━━━━━━━━━━━━━━━━╇━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━┩
│ Overall Health │ 87/100 │ ████████░░ Excellent │
│ Vulnerabilities │ 100/100 │ ██████████ Excellent │
│ Maintenance │ 100/100 │ ██████████ Excellent │
│ Quality │ 40/100 │ ████░░░░░░ Poor │
│ Complexity │ 95/100 │ █████████░ Excellent │
└─────────────────┴─────────┴──────────────────────┘
Vulnerabilities and staleness require live network calls (OSV.dev and PyPI's JSON API); pass --offline to skip them and get a deterministic score from local data only (dead-dependency detection and graph complexity).
SBOM export and signing
# Generate keys once
python3 -c "from pydependencycheck.sbom import SBOMSigner; SBOMSigner().generate_keys('signing-key.pem')"
# Export a signed SBOM
pydependencycheck export --format cyclonedx --sign --key signing-key.pem --output sbom.json
The SBOM carries a SHA-256 integrity hash and (when --sign is used) an RSA-SHA256 signature over the document, verifiable with SBOMSigner.verify_sbom().
CI gating with GitHub Actions
name: Dependency Check
on: [push, pull_request]
jobs:
check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v4
with:
python-version: '3.11'
- run: pip install pydependencycheck
- run: pydependencycheck scan . --save-snapshot
- run: pydependencycheck gate --min-health 50
- run: pydependencycheck export --format cyclonedx --output sbom.json
- uses: actions/upload-artifact@v3
with:
name: sbom
path: sbom.json
gate prints ::error/::warning/::notice GitHub Actions annotations automatically when GITHUB_ACTIONS is set, and always sets the process exit code (1 on failure), so it works as a real CI gate on any CI system, not just GitHub Actions.
OpenTelemetry
pydependencycheck health --otel
Defaults to a console exporter backed by the real OpenTelemetry SDK (ConsoleSpanExporter/ConsoleMetricExporter) -- genuine spans and metrics printed to stdout, no collector required. Pass --otel-exporter otlp|jaeger|prometheus to ship to real infrastructure if you have it configured; if the corresponding exporter package isn't installed, it falls back to console rather than silently doing nothing.
Architecture
Rust workspace (crates/) does the heavy lifting, exposed to Python via PyO3:
pydep-parser-- PEP 508 requirements/pyproject.toml parsing (extras, markers, every version operator)pydep-graph-- dependency graph construction, cycle detection, topological sort (petgraph)pydep-ast-- import extraction and dead-dependency detectionpydep-security-- OSV.dev vulnerability queries and risk scoringpydep-py-- PyO3 bindings tying it together aspydependencycheck._pydependencycheck
The Python package (python/pydependencycheck/) is the CLI, plus SBOM generation, license analysis, git integration, SQLite-backed snapshot storage, and OpenTelemetry instrumentation.
Testing: 45 Rust unit tests (cargo test --workspace) across all four crates, plus 126 Python tests (pytest tests/) covering the CLI end-to-end, the XSS fix, SBOM signing/verification, license classification, health scoring, and the SQLite storage layer.
Requirements
Python 3.8+ on Linux (x86_64), macOS (Intel/ARM), or Windows (x86_64).
License
Proprietary License - free to use with explicit attribution. See LICENSE for details.
When using PyDependencyCheck, include this attribution:
Powered by PyDependencyCheck (https://github.com/Mullassery/PyDependencyCheck)
Support
Release files for pydependencycheck 1.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pydependencycheck-1.3.0-cp313-cp313-macosx_11_0_arm64.whl | CPython 3.13 | CPython 3.13 | macOS 11.0+ ARM64 | Details |
| pydependencycheck-1.3.0-cp39-cp39-macosx_11_0_arm64.whl | CPython 3.9 | CPython 3.9 | macOS 11.0+ ARM64 | Details |
Total release size: 3.0 MB
Release files / pydependencycheck-1.3.0-cp313-cp313-macosx_11_0_arm64.whl
| Download URL | pydependencycheck-1.3.0-cp313-cp313-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.5 MB |
| Tags | CPython 3.13 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
b5642e609d9b3a7c13f068ca7b46445b2bdceed28af0dcb1d2bb0a0b1f06b6e2
|
|
BLAKE2b-256 checksum How to use checksums |
8404cad77038ccd1f0f454abba97c3a7335761620c60ab7fa2811010e8df6818
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|
Release files / pydependencycheck-1.3.0-cp39-cp39-macosx_11_0_arm64.whl
| Download URL | pydependencycheck-1.3.0-cp39-cp39-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.5 MB |
| Tags | CPython 3.9 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
99bc461ea9bc9d33ec708a2b024831bbbabd9bffd1ef25fca933e54db0f66e37
|
|
BLAKE2b-256 checksum How to use checksums |
a62279eb8911bb8c1da6bd6b0c729fe366b615e13deae70df8471463a20f4b89
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|