tesserakit-deps
Audit dependency manifests for pinning discipline, duplicates, and conflicts.
tessera-deps parses dependency manifests across ecosystems, classifies how tightly each dependency is pinned, and flags supply-chain hygiene issues. It reads manifests only: no installs, no lockfile resolution, no network.
Where tessera-repo lists that a manifest declares dependencies, tessera-deps analyses how they are declared.
Audit
tessera deps audit --input . --output ./out/deps_pack
Supported manifests: requirements*.txt, pyproject.toml, package.json, Cargo.toml, go.mod.
Artifacts written:
dependencies.jsonl one Dependency per declaration (ecosystem, scope, constraint, pinning)
index.md the inventory table
validation_report.md pinning + duplicate + conflict findings
coverage_report.md counts by pinning / ecosystem / scope
duplicates.md dependencies declared in more than one manifest
Pinning classification
- pinned — an exact version (
==1.2.3, npm1.2.3, cargo=1.2.3, gov1.2.3) - ranged — a bounded range (
>=,~=,^,~, ...) - unpinned — no constraint at all,
*, orlatest
Findings
unpinned_dependency— declared with no version constraintduplicate_dependency— same name declared in multiple manifests (same constraint)conflicting_constraint— same name declared with different constraints across manifestsdeclared_not_locked— a manifest dependency is absent from the lockfile (the lock is stale)locked_version_mismatch— a manifest pins an exact version that disagrees with the lockfilelockfile_missing— npm/cargo deps are declared but no lockfile exists (builds aren't reproducible)no_dependencies— nothing found
Lockfile parsing covers package-lock.json, yarn.lock, poetry.lock, and Cargo.lock.
Metadata
Release files for tesserakit-deps 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| tesserakit_deps-0.4.0.tar.gz | 8.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| tesserakit_deps-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 19.9 kB
Release files / tesserakit_deps-0.4.0.tar.gz
| Download URL | tesserakit_deps-0.4.0.tar.gz |
|---|---|
| Size | 8.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
64dff8edc800bf5994b9d503b0ff8b08d330e6448f91a324c99778b90825487b
|
|
BLAKE2b-256 checksum How to use checksums |
8be6c7a4de824ff91d0e548a5dadc2fee20b4894cb961c975c182dd1eb7e6606
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.11
|
Release files / tesserakit_deps-0.4.0-py3-none-any.whl
| Download URL | tesserakit_deps-0.4.0-py3-none-any.whl |
|---|---|
| Size | 11.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c7b762783f74bf50e4719b626b0c9db53d330d82dbe6bdb65168821fb12bcaa0
|
|
BLAKE2b-256 checksum How to use checksums |
6f220979ba1e38f71b4254626f8e7ef0d113dfd883d7fc3878173bac0804d893
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.11
|