🔍 qv
Diagnose why your Python project is unhealthy — understand the root cause and get safe, actionable fixes.
Installation • Quick Start • Features • CLI Commands • CI/CD Integration • Documentation
💡 Why qv?
Python projects rarely fail because of Python syntax. They fail because of ecosystem friction:
- Incompatible transitive dependency constraints that break your resolver.
- Missing dependencies you forgot to add to
pyproject.toml. - Docker containers running Python 3.10 while your team develops on 3.12.
- Silent circular imports that only crash at runtime when certain modules load.
Instead of parsing hundreds of lines of cryptic resolver logs, qv scans your project in milliseconds, pinpoints the root cause, shows the exact evidence, and gives you a copy-paste command to fix it.
🔍 qv
Project: payment-service
Python: 3.12.7
Package Manager: uv
🔴 1 Errors 🟡 1 Warnings 🟢 48 Checks Passed
┌────────────────── 🔴 DEP-001 Dependency constraint conflict ─────────────────┐
│ celery 5.4.0 requires kombu<5.4.0,>=5.3.0, but installed is kombu 5.5.2. │
│ │
│ Evidence: │
│ • celery declared requirement: kombu<5.4.0,>=5.3.0 │
│ • Installed kombu version: 5.5.2 in active environment │
│ │
│ Suggested fix: │
│ Upgrade celery or pin kombu to <5.4.0,>=5.3.0. │
│ $ uv add 'kombu<5.4.0,>=5.3.0' │
└──────────────────────────────────────────────────────────────────────────────┘
Health Score: 85/100
📦 Installation
Install python-qv into your virtual environment (provides the qv CLI):
# Using pip
pip install python-qv
# Using uv
uv add python-qv --dev
# Run directly without installing (via uvx or pipx)
uvx python-qv scan
# or
pipx run python-qv scan
🚀 Quick Start
1. Run a Health Scan
Run qv scan inside any Python repository:
qv scan
2. Understand Any Flagged Issue
Need more context on why a rule triggered? Run explain:
qv explain DEP-001
3. Add Project Configuration
To add default configuration to your pyproject.toml:
qv init
🔍 What It Detects
| Category | Rule ID | Description | Default Severity |
|---|---|---|---|
| Dependencies | DEP-001 |
Incompatible package version constraints across dependency tree | ERROR |
DEP-002 |
Third-party packages imported in code but missing from pyproject.toml |
ERROR |
|
DEP-003 |
Declared dependencies that are never imported anywhere in project | WARNING |
|
DEP-004 |
Package requires a Python version incompatible with target runtime | WARNING |
|
DEP-005 |
Installed virtualenv version does not match declared manifest pin | WARNING |
|
| Environment | ENV-001 |
Active interpreter version differs from project requires-python |
WARNING |
ENV-002 |
Dockerfile base image Python version differs from project runtime | WARNING |
|
ENV-003 |
CI matrix does not cover the Python versions declared in project | WARNING |
|
| Architecture | IMP-001 |
Circular import cycles across local modules | ERROR |
IMP-002 |
Unresolved relative or internal module imports | ERROR |
|
| Packaging | PKG-001 |
Missing PEP 621 metadata (name, version, etc.) | WARNING |
PKG-002 |
Invalid syntax or malformed keys in pyproject.toml |
ERROR |
👉 See full explanations and remediation steps in the Rules Catalog.
🛠️ CLI Commands
# Full project diagnostic scan
qv scan
# Scan another folder
qv scan ./services/billing
# Strict mode: fail CI on warnings as well as errors
qv scan --strict
# Output machine-readable formats
qv scan --json
qv scan --sarif -o results.sarif
# Run focused subsystem scans
qv dependency # Check package constraints & imports
qv environment # Check Python, Docker & CI version drift
qv architecture # Check for circular imports & dead paths
# Explain a rule
qv explain DEP-002
# Check installed version
qv version
👉 See detailed options in the CLI Reference.
⚙️ Configuration
Configure qv in your pyproject.toml:
[tool.qv]
# Override severity for any rule (error, warning, info, off)
[tool.qv.rules]
DEP-001 = "error"
DEP-003 = "warning"
ENV-002 = "info"
# Ignore specific rules
[tool.qv.ignore]
rules = ["DEP-004"]
# Exclude directories from scanning
[tool.qv.paths]
exclude = [
".venv",
"build",
"dist",
"legacy_scripts",
]
# Set expected target Python version
[tool.qv.runtime]
python = "3.12"
👉 Learn more in the Configuration Guide.
🤖 CI/CD Integration
GitHub Actions (with SARIF code scanning)
Add this step to your GitHub Actions workflow (.github/workflows/ci.yml):
name: Health & Dependency Scan
on: [push, pull_request]
jobs:
qv:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v3
# Run scan in CI mode
- name: Run qv
run: uv run qv scan --ci
# Optional: Generate SARIF report for GitHub Code Scanning
- name: Generate SARIF report
run: uv run qv scan --sarif -o qv.sarif
if: always()
- name: Upload SARIF to GitHub Security
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: qv.sarif
if: always()
👉 See full details in CI/CD Integration.
🎯 Design Principles
- Diagnose first. Explain second. Fix safely.
- No destructive auto-mutations: Remediations provide the exact commands/diffs for you to review and apply.
- Local-first & Blazing fast: Zero network calls required; scans complete in under a second.
- Package-manager agnostic: Works out of the box with
uv, Poetry,pip, PDM, and Pipenv.
📚 Complete Documentation
- 🚀 Getting Started Guide
- 📖 CLI Reference
- 📋 Diagnostic Rules Catalog
- ⚙️ Configuration Guide
- 🤖 CI/CD & SARIF Integration
- 🤝 Contributing Guidelines
📄 License
Distributed under the MIT License.
Metadata
Release files for python-qv 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| python_qv-0.1.0.tar.gz | 64.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| python_qv-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 97.1 kB
Release files / python_qv-0.1.0.tar.gz
| Download URL | python_qv-0.1.0.tar.gz |
|---|---|
| Size | 64.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
303a0aaff39e8f19e6630186ff4ee93f2b7825bbf5c9b1f564800c3f86f50c14
|
|
BLAKE2b-256 checksum How to use checksums |
7f52005aeda39179f44c2446a775e4b6be47067e64ee89310435dc3b674418b8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / python_qv-0.1.0-py3-none-any.whl
| Download URL | python_qv-0.1.0-py3-none-any.whl |
|---|---|
| Size | 32.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
201aa0094e419e1d63c9f36d6e29f14c9d8fe40f0f1d48d3b1f282c7893ca2f3
|
|
BLAKE2b-256 checksum How to use checksums |
9011f64d32e85c4b277fc99475e49221a5503f67e623e7adb4f9973eb68a4794
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency log