Skip to content
This repository has been archived by the owner on Apr 1, 2022. It is now read-only.

Latest commit



339 lines (312 loc) · 11.7 KB

File metadata and controls

339 lines (312 loc) · 11.7 KB


This is a modern approach to defining python project dependencies, providing very precise, complete dependency graphs for a python project.

Project Discovery

Find all files named Pipfile.lock


We parse Pipfile.lock -- a json-structured file -- to find:

  • sources - repositories/locations that can be referenced by packages
  • default - production dependencies
  • develop - development dependencies

Dependencies may contain an index field -- this is a reference to a repository in the top-level sources.

Dependencies contain pinned version information.

When possible, we use pipenv graph --json-tree to hydrate the edges between dependencies. This will fail unless pipenv install has been run in that directory.


  • Pipfile.lock does not report edges, if pipenv graph --json-tree fails, we will not be able to detect the edges between dependencies.

    • pipenv graph --json-tree relies on pipenv install being run in the directory beforehand. If that command was not run (such as in a freshly cloned repo), then the graph command will fail, which means that pipenv analysis will succeed, but with incomplete data (missing edges)
    • The graph command will also fail if pipenv is not installed or on the PATH.


Pipenv does a lot of work behind the scenes, so even a trivial example is quite large.

Pipfile (created by running pipenv install requests && pipenv install --dev pytest):

url = ""
verify_ssl = true
name = "pypi"

requests = "*"

pytest = "*"

Pipfile.lock (created at the same time as Pipfile above): This file is an example, and may not represent the exact versions you would find if you ran this example yourself.

    "_meta": {
        "hash": {
            "sha256": "03f05e808d849011739499ce042685cadfd6f14f4c6784ee3e6ad577b656437a"
        "pipfile-spec": 6,
        "requires": {
            "python_version": "3.6"
        "sources": [
                "name": "pypi",
                "url": "",
                "verify_ssl": true
    "default": {
        "certifi": {
            "hashes": [
            "version": "==2021.5.30"
        "chardet": {
            "hashes": [
            "version": "==4.0.0"
        "idna": {
            "hashes": [
            "version": "==2.10"
        "requests": {
            "hashes": [
            "index": "pypi",
            "version": "==2.25.1"
        "urllib3": {
            "hashes": [
            "version": "==1.26.6"
    "develop": {
        "attrs": {
            "hashes": [
            "version": "==21.2.0"
        "importlib-metadata": {
            "hashes": [
            "markers": "python_version < '3.8'",
            "version": "==4.6.0"
        "iniconfig": {
            "hashes": [
            "version": "==1.1.1"
        "packaging": {
            "hashes": [
            "version": "==20.9"
        "pluggy": {
            "hashes": [
            "version": "==0.13.1"
        "py": {
            "hashes": [
            "version": "==1.10.0"
        "pyparsing": {
            "hashes": [
            "version": "==2.4.7"
        "pytest": {
            "hashes": [
            "index": "pypi",
            "version": "==6.2.4"
        "toml": {
            "hashes": [
            "version": "==0.10.2"
        "typing-extensions": {
            "hashes": [
            "markers": "python_version < '3.8'",
            "version": "=="
        "zipp": {
            "hashes": [
            "version": "==3.4.1"

Output of pipenv graph --json-tree:

        "key": "pytest",
        "package_name": "pytest",
        "installed_version": "6.2.4",
        "required_version": "6.2.4",
        "dependencies": [
                "key": "attrs",
                "package_name": "attrs",
                "installed_version": "21.2.0",
                "required_version": ">=19.2.0",
                "dependencies": []
                "key": "importlib-metadata",
                "package_name": "importlib-metadata",
                "installed_version": "4.6.0",
                "required_version": ">=0.12",
                "dependencies": [
                        "key": "typing-extensions",
                        "package_name": "typing-extensions",
                        "installed_version": "",
                        "required_version": ">=3.6.4",
                        "dependencies": []
                        "key": "zipp",
                        "package_name": "zipp",
                        "installed_version": "3.4.1",
                        "required_version": ">=0.5",
                        "dependencies": []
                "key": "iniconfig",
                "package_name": "iniconfig",
                "installed_version": "1.1.1",
                "required_version": "Any",
                "dependencies": []
                "key": "pluggy",
                "package_name": "pluggy",
                "installed_version": "0.13.1",
                "required_version": ">=0.12,<1.0.0a1",
                "dependencies": [
                        "key": "importlib-metadata",
                        "package_name": "importlib-metadata",
                        "installed_version": "4.6.0",
                        "required_version": ">=0.12",
                        "dependencies": [
                                "key": "typing-extensions",
                                "package_name": "typing-extensions",
                                "installed_version": "",
                                "required_version": ">=3.6.4",
                                "dependencies": []
                                "key": "zipp",
                                "package_name": "zipp",
                                "installed_version": "3.4.1",
                                "required_version": ">=0.5",
                                "dependencies": []
                "key": "py",
                "package_name": "py",
                "installed_version": "1.10.0",
                "required_version": ">=1.8.2",
                "dependencies": []
                "key": "toml",
                "package_name": "toml",
                "installed_version": "0.10.2",
                "required_version": "Any",
                "dependencies": []
        "key": "requests",
        "package_name": "requests",
        "installed_version": "2.25.1",
        "required_version": "2.25.1",
        "dependencies": [
                "key": "certifi",
                "package_name": "certifi",
                "installed_version": "2021.5.30",
                "required_version": ">=2017.4.17",
                "dependencies": []
                "key": "chardet",
                "package_name": "chardet",
                "installed_version": "4.0.0",
                "required_version": ">=3.0.2,<5",
                "dependencies": []
                "key": "idna",
                "package_name": "idna",
                "installed_version": "2.10",
                "required_version": ">=2.5,<3",
                "dependencies": []
                "key": "urllib3",
                "package_name": "urllib3",
                "installed_version": "1.26.6",
                "required_version": ">=1.21.1,<1.27",
                "dependencies": []

Final graph from our analysis:


Note that request and all of its dependencies are marked as production dependencies, while pytest and all of its dependencies are marked as development dependencies (since pipenv makes no distinction about dev/test).

The versions are omitted here, but are tracked as part of the graph as well.