Skip to main content

PyPI Insiders

ci documentation pypi version gitter

Self-hosted PyPI server with automatic updates for Insiders versions of projects.

Motivation

Some open source projects follow the sponsorware release strategy, which means that new features are first exclusively released to sponsors as part of an "Insiders" version of the project. This Insiders version is usually a private fork of the public project.

To use the Insiders projects as dependencies, sponsors have two options:

  1. specify the dependency as a Git URL (HTTPS or SSH), or as a direct HTTPS URL to a build artifact
  2. build and store the artifact in a self-hosted PyPI-like index

The first option is problematic when sponsors' projects are also open source, because most of their contributors will probably not have access to the Insiders version. It means they won't be able to resolve the dependency, even less install it locally. As a result, maintainers must specify the public version of the project as a dependency, and override it with the Insiders version in Continuous Integration / Deployment.

In contrast, the second option allows maintainers to specify the dependency normally, i.e. using the same name/identifier as the public version. Maintainers/contributors with access to the Insiders version will resolve and get the Insiders version, while maintainers/contributors without access to the Insiders version will simply get the public one.

However, self-hosting a PyPI-like index, and building artifacts for each new Insiders version is not a trivial, straight-forward task: companies and organizations might already have such a setup (with an Artifactory server, a Google Cloud registry, etc.), but individual contributors often won't, and automatically updating repositories, building artifacts and uploading them requires custom scripts.

In both cases (company setup or individual contributor) PyPI Insiders comes to the rescue, and manages repository/package updates for you. It comes bundled with a PyPI-like index that you can serve locally, and it watches Insiders repositories, building and uploading distributions to your local index (or any other online index) for each new Insiders version getting published.

See below how to install and use PyPI Insiders!

Installation

pip install pypi-insiders

With uv:

uv tool install pypi-insiders

Usage

Run the server with:

pypi-insiders server start

The local PyPI server should be running:

pypi-insiders server status

Now, if you wish, you can configure your tools to use your local index by default:

export PIP_INDEX_URL=http://localhost:31411/simple/
export PDM_PYPI_URL=http://localhost:31411/simple/
export UV_INDEX_URL=http://localhost:31411/simple/

Your local index will give precedence to its own packages, and redirect to PyPI.org if it doesn't know the specified packages. It means that Insiders versions will always take precedence over public versions, even if the latter are higher (more recent).

Configuring your tools with environment variables makes it easy to temporarily "deactivate" your local index:

# This will install directly from PyPI.org.
env -u PIP_INDEX_URL pip install something
env -u PDM_PYPI_URL pdm sync
env -u UV_INDEX_URL uv sync

You can declare a shell alias to make things even simpler:

alias no-insiders='env -u PIP_INDEX_URL -u PDM_PYPI_URL -u UV_INDEX_URL'
no-insiders uv sync

Configure the repositories to watch:

pypi-insiders repos add pawamoy-insiders/devboard:devboard

The format is NAMESPACE/PROJECT:DISTRIBUTION_NAME. Only GitHub projects are supported for now.

List watched repositories:

pypi-insiders repos list

Remove watched repositories:

pypi-insiders repos remove pawamoy-insiders/devboard

Start/stop the local PyPI index, get the server status:

pypi-insiders server start
pypi-insiders server status
pypi-insiders server stop

Update all packages from watched repositories:

pypi-insiders update

Update a specific package:

pypi-insiders update pawamoy-insiders/devboard

Start/stop the watcher, get the watcher status:

pypi-insiders watcher start
pypi-insiders watcher status
pypi-insiders watcher stop

Show logs of the server/watcher:

pypi-insiders server logs
pypi-insiders watcher logs

Upload the packages to a private index that requires authentication.

pypi-insiders update --index-url <url> --index-user user --index-password <password>
pypi-insiders watcher start --index-url <url> --index-user user --index-password <password>

Sponsors

Metadata

Release files for pypi-insiders 1.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pypi-insiders 1.1.1
File Size Uploaded
pypi_insiders-1.1.1.tar.gz 42.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pypi-insiders 1.1.1
File Interpreter ABI Platform
pypi_insiders-1.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 82.0 kB

Release files / pypi_insiders-1.1.1.tar.gz

Download URL pypi_insiders-1.1.1.tar.gz
Size 42.2 kB
Tags Source
SHA-256 checksum
How to use checksums
1ca4a6f34832de75b0dc6f0a1a14e3e2dc0ed285e17f5c379ecf92214e0192c3
BLAKE2b-256 checksum
How to use checksums
f09b0faec61fc3fec9b28a438df25d3e945dda8d39169423e3a561ae24cf684a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.8

Release files / pypi_insiders-1.1.1-py3-none-any.whl

Download URL pypi_insiders-1.1.1-py3-none-any.whl
Size 39.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
fe70a3b8dd51afe3f75daa8e12901b6e438e9d891ed7d1a4f97942d740acc1b7
BLAKE2b-256 checksum
How to use checksums
34a366b2fdd492409e1db5dc3b561cae20ce3917bfade4654cedaebe235abb0a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.8

Release history Release notifications | RSS feed

This release

1.1.1 This release

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page