uvault
Development and vaulting workflow for uv VCS dependencies.
Secure your Python projects against deleted or force-pushed upstream commits. uvault automatically vaults transient VCS references (like GitHub PRs) into your organization's own repositories, while allowing developers to instantly switch dependencies into local editable mode—fully integrated with pyproject.toml and uv.
Key Features
- Vaulting of Commits: Never lose code again! Upstream pull requests and branches can be force-pushed or deleted.
uvaultfetches the exact commits your project depends on and pushes them as immutable tags to your own organization's vault repository. - Easy Local Development: Switch any VCS dependency to local "editable" mode in seconds.
uvault developclones the package locally and seamlessly configuresuvto use your local copy so you can test changes and contribute back. - Automatic GitHub Forking: When a dependency's repository doesn't exist in your vault organization,
uvaultautomatically forks the upstream repository using the GitHub API (via the[github]extra), making the setup completely transparent. - Status Monitoring: Instantly check the health of all your VCS dependencies.
uvault statusshows if PRs are merged or closed, flags new remote commits, and automatically detects orphaned commits caused by upstream force-pushes.
Documentation
The complete documentation is available in the docs/ folder:
- Quickstart & Key Features - Learn what
uvaultis and how to get started quickly. - How-To Guides - Step-by-step guides for installing and using
uvaultin your day-to-day workflow. - CLI & Configuration Reference - Detailed information on
pyproject.tomlconfiguration ([tool.uvault]) and all CLI commands (sync,add,develop).
Contributing
Contributions are welcome! If you're interested in improving uvault, please check out our Contributing Guide for details on setting up your development environment, running tests, and submitting PRs.
Credits & Acknowledgements
A huge thank you to Stéphane Bidoul for his continuous inspiration, and particularly for the work on pip-preserve-requirements which strongly influenced the vision and design of this project.
Metadata
Release files for uvault 0.7.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| uvault-0.7.0.tar.gz | 127.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| uvault-0.7.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 149.4 kB
Release files / uvault-0.7.0.tar.gz
| Download URL | uvault-0.7.0.tar.gz |
|---|---|
| Size | 127.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
01af00c5a3f77d5b66b5a9b17f0db17b033aaa0db487880576f72c1117b443ef
|
|
BLAKE2b-256 checksum How to use checksums |
6c0e47ba50909ff14e403258f9d9528e0a0234e7c896c401b52ae0dda6fb89b8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / uvault-0.7.0-py3-none-any.whl
| Download URL | uvault-0.7.0-py3-none-any.whl |
|---|---|
| Size | 22.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5d5fd0a7d51d3babe9c3c9ccea88504f449a3705cbcc822395ff314743d06ed8
|
|
BLAKE2b-256 checksum How to use checksums |
75c2e3eba2982a62f1ff78a34764d6ae8b2c1fca17ab898ac335afbcbd4a352c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log