mirror of
https://github.com/vinta/awesome-python.git
synced 2026-10-08 00:53:22 +08:00
Merge branch 'audit-all'
This commit is contained in:
+3
-1
@@ -8,7 +8,7 @@ All submissions must satisfy **ALL** of these:
|
||||
|
||||
1. **Serves Python Developers**: Python developers use it in their Python work. Implementation language and packaging are irrelevant — uv and ty are written in Rust, and agent skill packs are markdown, yet all belong; a pure-Python project nobody uses in Python work does not.
|
||||
2. **Active**: Commits within the last 12 months
|
||||
3. **Stable**: Production-ready, not alpha/beta/experimental
|
||||
3. **Stable**: Production-ready, not alpha/beta/experimental. A PyPI "Development Status" classifier alone does not decide this; judge by releases, documentation, and production use.
|
||||
4. **Documented**: Clear README with examples and use cases
|
||||
5. **Established**: Repository at least 1 month old
|
||||
|
||||
@@ -31,6 +31,8 @@ Hard maximum: 5 entries per use case. This is a qualitative bar first and a nume
|
||||
|
||||
**Standard library**: a standard-library module is listed only where the stdlib is itself the obvious choice for the use case (tomllib yes, unittest no).
|
||||
|
||||
**Python versions**: missing support for the newest Python releases is not by itself grounds for removal while the entry still has a large user base; it can place the entry in the Second Tier instead.
|
||||
|
||||
**Evidence**: admission is decided by maintainer editorial judgment, informed primarily by PyPI download counts rather than GitHub stars. Judgment overrides the signal's known failure modes (CI-inflated counts, model releases consumed as weights rather than pip installs, large-but-specific audiences misread as "niche"). The maintainer's decision is final.
|
||||
|
||||
Looking for an exhaustive catalog instead? Follow the awesome-\* lists linked under individual entries (for example awesome-python-testing) — they exist precisely so this list doesn't have to be one.
|
||||
|
||||
+16
-5
@@ -29,11 +29,7 @@ Entries admitted despite the Stable quality requirement, by maintainer decision:
|
||||
- zensical -- admitted 2026-08-23 at version 0.0.57, PyPI classifier `Development Status :: 3 - Alpha`, with no 1.0 target announced. Admitted as a challenger displacing mkdocs because the Documentation section was carrying a dying upstream: the Material for MkDocs team's announcement of 2025-11-05 put Material into maintenance mode for twelve months and called MkDocs itself unmaintained since 2024-08 and a supply chain risk. Re-check when 1.0 lands.
|
||||
- openviking -- admitted 2026-08-25 (PR #3302) at version 0.4.16, PyPI classifier `Development Status :: 3 - Alpha`, with a README that said "OpenViking is still in its early stages". Admitted as a Data Layer challenger because the adoption is real: 459,446 downloads/month on pypistats (mirror-excluded) on 2026-08-24, and releases every few days. Re-check when 1.0 lands.
|
||||
- claude-agent-sdk -- kept 2026-10-01 in the AI and Agents audit at version 0.2.163, PyPI classifier `Development Status :: 3 - Alpha`. Kept as a Vendor Agent SDKs obvious choice because the adoption is real: 30,033,689 downloads/month on ClickPy on 2026-10-01, up from 1.2M in March 2026 on pypistats. Re-check when 1.0 lands.
|
||||
- keras -- kept 2026-10-02 in the AI & ML audit as a Deep Learning Frameworks Second Tier challenger at version 3.15.1, PyPI classifier `Development Status :: 4 - Beta`. Kept because Keras 3 is a production multi-backend API; the classifier lags the project.
|
||||
- stanza -- kept 2026-10-02 in the AI & ML audit as an NLP General challenger at version 1.15.0, PyPI classifier `Development Status :: 4 - Beta`. Kept because it is Stanford NLP's official library with releases through 2026-10-01; the classifier lags the project.
|
||||
- kornia -- kept 2026-10-02 in the AI & ML audit as a Computer Vision General challenger at version 0.8.3, PyPI classifier `Development Status :: 4 - Beta`. Kept on 2,181,803 downloads/month on pypistats; the classifier lags the project.
|
||||
- implicit -- kept 2026-10-02 in the AI & ML audit as a Recommender Systems obvious choice at version 0.7.3, PyPI classifier `Development Status :: 4 - Beta`. Kept on 234,833 downloads/month on pypistats and cp314 wheels; the classifier lags the project.
|
||||
- statsforecast -- admitted 2026-10-02 in the AI & ML audit as a Time Series Forecasting obvious choice at version 2.1.1, PyPI classifier `Development Status :: 4 - Beta`. Admitted on 1,339,344 downloads/month on pypistats; the classifier lags the project.
|
||||
- uv-audit -- kept 2026-08-16 as a Supply Chain Security entry, recorded 2026-10-02. uv itself prints "`uv audit` is experimental and may change without warning". Kept because it is part of uv, the obvious package manager. Re-check when uv drops the experimental notice.
|
||||
|
||||
### Challenger Exceptions
|
||||
|
||||
@@ -41,14 +37,29 @@ Entries admitted as challengers without adoption-trajectory evidence, by maintai
|
||||
|
||||
- seleniumbase -- admitted 2026-08-16 (PR #3284) as a Browser Automation challenger. It wraps selenium, the successor trajectory in the use case belongs to playwright, and its distinct value is its stealth/UC mode. Admitted because that stealth value counts toward Browser Automation.
|
||||
- semantica -- kept 2026-10-01 in the AI and Agents audit as a Data Layer challenger at 16,582 downloads/month on ClickPy, with no adoption-trajectory evidence found. Kept by maintainer decision.
|
||||
- jev-ultrafast -- kept 2026-09-24 as a Web Scraping Frameworks challenger, recorded 2026-10-02. Admitted while the repo was under a month old and not on PyPI, so it has no download signal and no adoption-trajectory evidence; its README calls it an MVP and it needs a hosted TypeSafe API key. Kept by maintainer decision.
|
||||
|
||||
### Cap Exceptions
|
||||
|
||||
Use cases holding more than 5 entries, by maintainer decision:
|
||||
|
||||
- Asynchronous Programming > Async I/O -- 6 entries since the 2026-08-16 split (19875cf), recorded 2026-10-02.
|
||||
- Code Analysis > Linters and Formatters -- 6 entries since Security Linters merged in on 2026-08-16 (3290ce5), recorded 2026-10-02.
|
||||
- Package Management > Package Managers -- 6 entries since the subcategory was minted on 2026-08-16 (1b51907), recorded 2026-10-02.
|
||||
|
||||
### Mature-stable Keeps
|
||||
|
||||
These entries sit past the 12-month activity requirement without an override. Each one is kept by editorial judgment: mature, stable, and no successor exists.
|
||||
|
||||
- annoy -- kept 2026-10-02 in the AI & ML audit, last push 2025-10-29. Unlike the others it has a successor, Spotify's own Voyager (2023), but kept by maintainer decision on 911,913 downloads/month on pypistats.
|
||||
- blinker -- recorded 2026-10-02 ahead of its activity-line crossing on 2026-11-19 (last push 2025-11-19, last release 1.9.0 on 2024-11-08). Flask requires it.
|
||||
- diskcache -- kept 2026-10-02, last push 2024-08-10, last release 5.6.3 (2023-08-31). Kept despite an unpatched pickle deserialization advisory, CVE-2025-69872 (GHSA-w8v5-vhqr-4h9v), on 25,526,045 downloads/month on ClickPy.
|
||||
- django-rules -- recorded 2026-10-02 ahead of its activity-line crossing on 2026-10-11 (last push 2025-10-11, last release 3.5 on 2024-09-02).
|
||||
- ftfy
|
||||
- httpie -- kept 2026-08-16, recorded 2026-10-02. Last commit 2024-12-17, last release 3.2.4 on 2024-11-01.
|
||||
- itsdangerous
|
||||
- jieba
|
||||
- jinja
|
||||
- python-pptx -- kept 2026-10-02, last commit 2024-08-06, last release 1.0.2 on 2024-08-07. No successor for generating .pptx files.
|
||||
- schedule -- kept 2026-08-16, recorded 2026-10-02. Last commit 2024-05-25.
|
||||
- sortedcontainers
|
||||
|
||||
@@ -3,6 +3,7 @@
|
||||
"azure-sdk-for-python": { "package": null, "reason": "monorepo umbrella; ships as many azure-* packages, no single package represents it", "badge": "Multiple on PyPI" },
|
||||
"cloud-init": { "package": null, "reason": "installed via distro images, not pip" },
|
||||
"concurrent-futures": { "package": null, "reason": "stdlib module" },
|
||||
"conda": { "package": null, "reason": "installed via Miniforge or Anaconda installers; PyPI conda is a stale 2017 upload" },
|
||||
"cpython": { "package": null, "reason": "not pip-installable; the cpython PyPI name was squatted" },
|
||||
"devpi": { "package": "devpi-server", "reason": "devpi is a deprecated metapackage; the server package carries real usage" },
|
||||
"difflib": { "package": null, "reason": "stdlib module" },
|
||||
@@ -23,6 +24,7 @@
|
||||
"pangu-py": { "package": "pangu", "reason": null },
|
||||
"playwright-python": { "package": "playwright", "reason": null },
|
||||
"pyenv": { "package": null, "reason": "installed via git/homebrew; PyPI pyenv is a defunct shim" },
|
||||
"pyodide": { "package": null, "reason": "runs in the browser from a CDN or npm; PyPI pyodide is a 0.0.2 placeholder from 2021" },
|
||||
"pypy": { "package": null, "reason": "interpreter distributed via pypy.org, not pip" },
|
||||
"python-patterns": { "package": null, "reason": "reference repo, not a package; PyPI name held by unrelated 2012 project" },
|
||||
"pytorch": { "package": "torch", "reason": "PyPI pytorch is a squatter; real package is torch" },
|
||||
|
||||
@@ -3,8 +3,10 @@
|
||||
"/categories/ai-and-agents/pre-trained-models-and-inference/": "/categories/ai-and-agents/pre-trained-models/",
|
||||
"/categories/cli-tools/productivity-tools/": "/categories/cli-tools/",
|
||||
"/categories/code-analysis/code-linters/": "/categories/code-analysis/linters-and-formatters/",
|
||||
"/categories/code-analysis/type-annotations-generators/": "/categories/code-analysis/",
|
||||
"/categories/data-analysis/financial-data/": "/categories/data-ingestion-etl/financial-data/",
|
||||
"/categories/distributed-computing/batch-processing/": "/categories/distributed-computing/",
|
||||
"/categories/gui-development/terminal/": "/categories/cli-development/tui-frameworks/",
|
||||
"/categories/gui-development/wrappers/": "/categories/gui-development/",
|
||||
"/categories/web-servers/rpc/": "/categories/web-apis/rpc/"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user