-
Notifications
You must be signed in to change notification settings - Fork 0
Home
depsmith prepares, reviews and applies dependency updates for a repository. One Rust engine is shared by a command-line tool and a typed Python API. Each target is resolved by its native package manager inside a stage (a disposable copy of the repository), so you review exact file and dependency changes before anything is written, and the reviewed files are applied without resolving again.
Supported today: Pixi (pixi.toml and Pixi-managed pyproject.toml),
GitHub Actions workflow references, Cargo (Cargo.lock owners),
conda (environment.yml locked with conda-lock), uv
(pyproject.toml locked with uv.lock) and npm (package.json locked
with package-lock.json). depsmith init checks the native
tools your targets use and can install the missing ones.
- Getting started: install, check a project, apply updates.
-
Configuration:
depsmith.toml, saved targets and options. - Reviewing and applying: proposals, stale inputs, partial application and recovery.
- Pixi adapter: updates, upgrades, suggestions and acceptance.
- GitHub Actions adapter: release lines, commit pins and unresolved references.
- Cargo adapter: lock owners, MSRV-aware updates, suggestions and acceptance.
-
Conda adapter: conda-lock, sharded repodata evidence and
pip:requirements. - uv adapter: uv workspaces, Git pins, index evidence and acceptance.
-
npm adapter: npm workspaces, Git pins,
--beforecooldowns, registry evidence and acceptance. - Vulnerability scanning: baseline comparison, identities, policy and suppressions.
- CI integration: noninteractive jobs, reports and exit statuses.
- Troubleshooting: common errors and what to do.
- CLI reference and Python API, generated from the code.
Terms follow the project glossary,
CONTEXT.md.