From 0b75c7806dcee6356e78899ffee184de75281f5f Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:36:53 +0800 Subject: [PATCH 01/50] docs: judge stability by the project, not its PyPI classifier CONTRIBUTING's Stable requirement read as "not alpha/beta", so about 40 production-used entries (fastapi, uvicorn, keras, statsmodels, numba, and others) failed it on their PyPI Development Status classifier alone, and each needed an audit-log exception. Co-Authored-By: Claude --- CONTRIBUTING.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index d66b00d9..937d8ee9 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -8,7 +8,7 @@ All submissions must satisfy **ALL** of these: 1. **Serves Python Developers**: Python developers use it in their Python work. Implementation language and packaging are irrelevant — uv and ty are written in Rust, and agent skill packs are markdown, yet all belong; a pure-Python project nobody uses in Python work does not. 2. **Active**: Commits within the last 12 months -3. **Stable**: Production-ready, not alpha/beta/experimental +3. **Stable**: Production-ready, not alpha/beta/experimental. A PyPI "Development Status" classifier alone does not decide this; judge by releases, documentation, and production use. 4. **Documented**: Clear README with examples and use cases 5. **Established**: Repository at least 1 month old From 58c1312af3519d0e8d0a05e3b53c97f24dd43644 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:37:28 +0800 Subject: [PATCH 02/50] docs: treat missing Python version support as a tier signal No written rule covered Python version support, so audits treated a missing Python 3.14 wheel as grounds to drop entries that still have millions of users on older Pythons. Co-Authored-By: Claude --- CONTRIBUTING.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 937d8ee9..65b46c5b 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -31,6 +31,8 @@ Hard maximum: 5 entries per use case. This is a qualitative bar first and a nume **Standard library**: a standard-library module is listed only where the stdlib is itself the obvious choice for the use case (tomllib yes, unittest no). +**Python versions**: missing support for the newest Python releases is not by itself grounds for removal while the entry still has a large user base; it can place the entry in the Second Tier instead. + **Evidence**: admission is decided by maintainer editorial judgment, informed primarily by PyPI download counts rather than GitHub stars. Judgment overrides the signal's known failure modes (CI-inflated counts, model releases consumed as weights rather than pip installs, large-but-specific audiences misread as "niche"). The maintainer's decision is final. Looking for an exhaustive catalog instead? Follow the awesome-\* lists linked under individual entries (for example awesome-python-testing) — they exist precisely so this list doesn't have to be one. From 983a11aefd576bb4ac249d1e9aeae5d0266c1c04 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:37:51 +0800 Subject: [PATCH 03/50] audit: sweep Web Development, reorder Web APIs and reword gunicorn In Web APIs > Framework Agnostic, connexion (4.26M downloads/month) sat above strawberry (5.76M) against the downloads-order rule, and gunicorn's line omitted the native ASGI worker it has shipped stable since 25.1.0. hypercorn stays in Second Tier (last position, unchanged) under the new Python-version rule instead of being dropped. Co-Authored-By: Claude --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index d6e18e31..692ed177 100644 --- a/README.md +++ b/README.md @@ -283,8 +283,8 @@ _Libraries for building RESTful, GraphQL, and RPC APIs._ - [apiflask](https://github.com/apiflask/apiflask) - A lightweight Python web API framework based on Flask, supporting marshmallow schemas and Pydantic models. - Framework Agnostic - [fastapi](https://github.com/fastapi/fastapi) - A modern, fast, web framework for building APIs with standard Python type hints. - - [connexion](https://github.com/spec-first/connexion) - A spec-first framework that automatically handles requests based on your OpenAPI specification. - [strawberry](https://github.com/strawberry-graphql/strawberry) - A GraphQL library that leverages Python type annotations for schema definition. + - [connexion](https://github.com/spec-first/connexion) - A spec-first framework that automatically handles requests based on your OpenAPI specification. - RPC - [grpcio](https://github.com/grpc/grpc) - HTTP/2-based RPC framework with Python bindings, built by Google. @@ -297,7 +297,7 @@ _ASGI and WSGI compatible web servers._ - [granian](https://github.com/emmett-framework/granian) - A Rust HTTP server for Python applications built on top of Hyper and Tokio, supporting WSGI/ASGI/RSGI. - [hypercorn](https://github.com/pgjones/hypercorn) - An ASGI and WSGI Server based on Hyper libraries and inspired by Gunicorn. - WSGI - - [gunicorn](https://github.com/benoitc/gunicorn) - Pre-forked, ported from Ruby's Unicorn project. + - [gunicorn](https://github.com/benoitc/gunicorn) - A pre-fork WSGI server with a native ASGI worker, ported from Ruby's Unicorn project. - [waitress](https://github.com/Pylons/waitress) - Multi-threaded, powers Pyramid. ### WebSocket From 5990a2f18c087012b6f983cf4fda0fae17144541 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:38:03 +0800 Subject: [PATCH 04/50] feat: add flask-restx to Web APIs > Flask Web APIs > Flask listed only apiflask (172,781 downloads/month) while flask-restx, the most-installed Flask API framework at 1,162,703 (pypistats 2026-10-02), was missing. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 692ed177..47e6b32a 100644 --- a/README.md +++ b/README.md @@ -280,6 +280,7 @@ _Libraries for building RESTful, GraphQL, and RPC APIs._ - [strawberry-django](https://github.com/strawberry-graphql/strawberry-django) - Strawberry GraphQL integration with Django. - [django-modern-rest](https://github.com/wemake-services/django-modern-rest) - Modern REST with speed, types, async, `msgspec`, `pydantic` and other goodies! - Flask + - [flask-restx](https://github.com/python-restx/flask-restx) - Fully featured framework for fast, easy and documented API development with Flask. - [apiflask](https://github.com/apiflask/apiflask) - A lightweight Python web API framework based on Flask, supporting marshmallow schemas and Pydantic models. - Framework Agnostic - [fastapi](https://github.com/fastapi/fastapi) - A modern, fast, web framework for building APIs with standard Python type hints. From f2f776701adfc127364d23813ccf320dbdbcbb8e Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:38:15 +0800 Subject: [PATCH 05/50] feat: add flask-smorest to Web APIs > Flask Web APIs > Flask lacked marshmallow-code's flask-smorest, the second most-installed Flask API framework, so the challenger apiflask sat above a more widely used entry. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 47e6b32a..c848ac62 100644 --- a/README.md +++ b/README.md @@ -281,6 +281,7 @@ _Libraries for building RESTful, GraphQL, and RPC APIs._ - [django-modern-rest](https://github.com/wemake-services/django-modern-rest) - Modern REST with speed, types, async, `msgspec`, `pydantic` and other goodies! - Flask - [flask-restx](https://github.com/python-restx/flask-restx) - Fully featured framework for fast, easy and documented API development with Flask. + - [flask-smorest](https://github.com/marshmallow-code/flask-smorest) - A Flask/Marshmallow-based REST API framework with automatic OpenAPI documentation. - [apiflask](https://github.com/apiflask/apiflask) - A lightweight Python web API framework based on Flask, supporting marshmallow schemas and Pydantic models. - Framework Agnostic - [fastapi](https://github.com/fastapi/fastapi) - A modern, fast, web framework for building APIs with standard Python type hints. From 8d0186855ddd161c075154b99fb796b8bcea302b Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:38:28 +0800 Subject: [PATCH 06/50] feat: add whitenoise to Web Asset Management Web Asset Management omitted whitenoise, the standard static-file server for Django and WSGI production setups and the most-installed tool in the use case. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index c848ac62..295c13b6 100644 --- a/README.md +++ b/README.md @@ -322,6 +322,7 @@ _Libraries for rendering text and HTML from templates._ _Tools for managing, storing, compressing and minifying website assets._ +- [whitenoise](https://github.com/evansd/whitenoise) - Radically simplified static file serving for WSGI applications, with compression and caching headers. - [django-storages](https://github.com/jschneier/django-storages) - A collection of custom storage back ends for Django. - [django-compressor](https://github.com/django-compressor/django-compressor) - Compresses linked and inline JavaScript or CSS into a single cached file. From c460044aa388a32955e9a4e3d9180d5c1ccc871c Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:38:37 +0800 Subject: [PATCH 07/50] feat: add sqladmin to Admin Panels Admin Panels had no admin for FastAPI/Starlette apps. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 295c13b6..e4ba4895 100644 --- a/README.md +++ b/README.md @@ -347,6 +347,7 @@ _Libraries for administrative interfaces._ - [flask-admin](https://github.com/pallets-eco/flask-admin) - Simple and extensible administrative interface framework for Flask. - [django-unfold](https://github.com/unfoldadmin/django-unfold) - A modern Django admin theme for building dashboards, internal tools, and business applications. +- [sqladmin](https://github.com/smithyhq/sqladmin) - An admin interface for SQLAlchemy models in FastAPI and Starlette. - [django-grappelli](https://github.com/sehmaschine/django-grappelli) - A jazzy skin for the Django Admin-Interface. ### CMS From 1c1994251d7b8429ec9372492b6efc48c26525c5 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:39:00 +0800 Subject: [PATCH 08/50] audit: sweep HTTP Clients, promote httpx2 over httpx httpx held an obvious-choice slot with no stable release since 0.28.1 and its maintainer closed issues and discussions, while httpx2, Pydantic's same-API continuation, sat last despite openai, anthropic, huggingface-hub, mcp and langsmith now requiring it. Co-Authored-By: Claude --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index e4ba4895..edad28bb 100644 --- a/README.md +++ b/README.md @@ -378,10 +378,10 @@ _Libraries for working with HTTP._ - Clients - [requests](https://github.com/psf/requests) - HTTP Requests for Humans. - - [httpx](https://github.com/encode/httpx) - A next generation HTTP client for Python. - [aiohttp](https://github.com/aio-libs/aiohttp) - Asynchronous HTTP client/server framework for asyncio and Python. - - [urllib3](https://github.com/urllib3/urllib3) - An HTTP library with thread-safe connection pooling, file post, and more. - [httpx2](https://github.com/pydantic/httpx2) - HTTP/1.1 and HTTP/2 client with sync and async APIs, maintained by Pydantic ([httpx](https://github.com/encode/httpx) fork). + - [urllib3](https://github.com/urllib3/urllib3) - An HTTP library with thread-safe connection pooling, file post, and more. + - [httpx](https://github.com/encode/httpx) - A next generation HTTP client for Python. - URL Manipulation - [yarl](https://github.com/aio-libs/yarl) - Yet another URL library. From 12f7b2b5f6fc034d3de772e95f2a7f58887b785c Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:39:14 +0800 Subject: [PATCH 09/50] audit: sweep Web Scraping, replace html2text with markdownify Removed: html2text (12,324,912 downloads/month, pypistats 2026-10-02): last release 2025-04-15, last commit 2025-10-28, GPL-3.0, and markdownify does the same HTML-to-Markdown job at 52,097,079/month (about 38M after markitdown's dependency pull). Content Extraction now reads markdownify, feedparser, trafilatura. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index edad28bb..91ced2f0 100644 --- a/README.md +++ b/README.md @@ -396,8 +396,8 @@ _Libraries to automate web scraping and extract web content._ - [stagehand](https://github.com/browserbase/stagehand) - A fast and token-efficient browser automation SDK to extract data and perform self-healing actions on web pages. - [jev-ultrafast](https://github.com/browser-use/jev-ultrafast) - A fast browser agent that picks actions from an indexed table of page elements, using a small LLM only to type text. - Content Extraction + - [markdownify](https://github.com/matthewwithanm/python-markdownify) - Convert HTML to Markdown, with customizable tag handling. - [feedparser](https://github.com/kurtmckee/feedparser) - Universal feed parser. - - [html2text](https://github.com/Alir3z4/html2text) - Convert HTML to Markdown-formatted text. - [trafilatura](https://github.com/adbar/trafilatura) - A tool for gathering text and metadata from the web, with built-in content filtering. ### Email From 00b3c61ca91d74e39b2ad0abb0dd70ab1bc431c3 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:39:24 +0800 Subject: [PATCH 10/50] feat: add aiosmtplib to Email Email listed only yagmail, a Gmail-focused wrapper, while aiosmtplib, the general asyncio SMTP client, was missing. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 91ced2f0..c379205f 100644 --- a/README.md +++ b/README.md @@ -404,6 +404,7 @@ _Libraries to automate web scraping and extract web content._ _Libraries for sending email._ +- [aiosmtplib](https://github.com/cole/aiosmtplib) - An asyncio SMTP client. - [yagmail](https://github.com/kootenpv/yagmail) - Yet another Gmail/SMTP client. **Database & Storage** From 28479e3cfe7c602a53aebfa441471da1169a2f41 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:39:35 +0800 Subject: [PATCH 11/50] feat: add django-anymail to Email Email had no answer for sending through transactional email services from Django without vendor lock-in. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index c379205f..cf8b65d2 100644 --- a/README.md +++ b/README.md @@ -405,6 +405,7 @@ _Libraries to automate web scraping and extract web content._ _Libraries for sending email._ - [aiosmtplib](https://github.com/cole/aiosmtplib) - An asyncio SMTP client. +- [django-anymail](https://github.com/anymail/django-anymail) - Django email backends and webhooks for transactional email services such as Amazon SES, Mailgun, Postmark, Resend, and SendGrid. - [yagmail](https://github.com/kootenpv/yagmail) - Yet another Gmail/SMTP client. **Database & Storage** From a309758896265bcb02eaa888929bb63a25888465 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:39:55 +0800 Subject: [PATCH 12/50] audit: sweep Database, drop pixeltable Removed: pixeltable (4,356 downloads/month, pypistats 2026-10-02): a data engine that runs an embedded PostgreSQL with one writer process, not an in-process vector database, with no adoption trajectory for a challenger slot. Also: lancedb (7,888,645) moves above chromadb (6,619,378) to follow the downloads order. Co-Authored-By: Claude --- README.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/README.md b/README.md index cf8b65d2..595f5fe6 100644 --- a/README.md +++ b/README.md @@ -459,10 +459,9 @@ _In-process databases usable directly from Python._ - [duckdb](https://github.com/duckdb/duckdb) - An in-process SQL OLAP database management system; optimized for analytics and fast queries, similar to SQLite but for analytical workloads. - [chdb](https://github.com/chdb-io/chdb) - In-process OLAP SQL engine with the full ClickHouse dialect, zero-copy pandas/Arrow interop, and federation to remote ClickHouse clusters via `remoteSecure()`. - Vector - - [chromadb](https://github.com/chroma-core/chroma) - An open-source embedding database for building AI applications with embeddings and semantic search. - [lancedb](https://github.com/lancedb/lancedb) - A developer-friendly embedded retrieval database for multimodal AI. + - [chromadb](https://github.com/chroma-core/chroma) - An open-source embedding database for building AI applications with embeddings and semantic search. - [zvec](https://github.com/alibaba/zvec) - A lightweight, in-process vector database that embeds directly into applications. - - [pixeltable](https://github.com/pixeltable/pixeltable) - Declarative multimodal AI data engine for tables, computed columns, and embedding search. - Key-Value & Document - [tinydb](https://github.com/msiemens/tinydb) - A tiny, document-oriented database. From b4561c3b220ff2ca72c9ccc6b9a31c5638020cac Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:40:09 +0800 Subject: [PATCH 13/50] style: audit Database & Storage placement, wording, and order django-mongodb-backend, a Django ORM backend rather than a database driver, sat under Database Drivers. psycopg's line called it "the most popular PostgreSQL adapter", false for psycopg 3 (psycopg2-binary plus psycopg2 total about 268M downloads/month vs psycopg 122.7M). django-cacheops (2,032,868) sat below dogpile.cache (1,913,993) in Caching, and elasticsearch (34,739,455) above opensearch-py (38,565,351) in Search, both against the downloads order. Co-Authored-By: Claude --- README.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 595f5fe6..b398cf2e 100644 --- a/README.md +++ b/README.md @@ -424,6 +424,7 @@ _Libraries that implement Object-Relational Mapping or data mapping techniques._ - [pynamodb](https://github.com/pynamodb/PynamoDB) - A Pythonic interface for [Amazon DynamoDB](https://aws.amazon.com/dynamodb/). - [mongoengine](https://github.com/MongoEngine/mongoengine) - A Python Object-Document-Mapper for working with MongoDB. - [beanie](https://github.com/BeanieODM/beanie) - An asynchronous Python object-document mapper (ODM) for MongoDB. + - [django-mongodb-backend](https://github.com/mongodb/django-mongodb-backend) - Official MongoDB database backend for Django. ### Database Drivers @@ -433,7 +434,7 @@ _Libraries for connecting and operating databases._ - [pymysql](https://github.com/PyMySQL/PyMySQL) - A pure-Python MySQL and MariaDB client library, based on PEP 249. - [mysqlclient](https://github.com/PyMySQL/mysqlclient) - MySQL and MariaDB connector ([MySQLdb1](https://github.com/farcepest/MySQLdb1) fork). - PostgreSQL - [awesome-postgres](https://github.com/dhamaniasad/awesome-postgres) - - [psycopg](https://github.com/psycopg/psycopg) - The most popular PostgreSQL adapter for Python. + - [psycopg](https://github.com/psycopg/psycopg) - A PostgreSQL adapter for Python, the successor to psycopg2. - [asyncpg](https://github.com/MagicStack/asyncpg) - A fast PostgreSQL Database Client Library for Python/asyncio. - SQLite - [awesome-sqlite](https://github.com/planetopendata/awesome-sqlite) - [sqlite3](https://docs.python.org/3/library/sqlite3.html) - (Python standard library) SQLite interface compliant with DB-API 2.0. @@ -449,7 +450,6 @@ _Libraries for connecting and operating databases._ - [redis](https://github.com/redis/redis-py) - The Python client for Redis. - [pymongo](https://github.com/mongodb/mongo-python-driver) - The official Python client for MongoDB. - [cassandra-driver](https://github.com/apache/cassandra-python-driver) - The Python Driver for Apache Cassandra. - - [django-mongodb-backend](https://github.com/mongodb/django-mongodb-backend) - Official MongoDB database backend for Django. ### Database @@ -472,15 +472,15 @@ _Libraries for caching data._ - [cachetools](https://github.com/tkem/cachetools) - Extensible memoizing collections and decorators. - [diskcache](https://github.com/grantjenks/python-diskcache) - SQLite and file backed cache backend, compatible with Django. - [hishel](https://github.com/karpetrosyan/hishel) - RFC 9111 compliant HTTP caching for clients like httpx and requests and servers like FastAPI, with sync and async support. -- [dogpile.cache](https://github.com/sqlalchemy/dogpile.cache) - dogpile.cache is a next generation replacement for Beaker made by the same authors. - [django-cacheops](https://github.com/Suor/django-cacheops) - A slick ORM cache with automatic granular event-driven invalidation. +- [dogpile.cache](https://github.com/sqlalchemy/dogpile.cache) - dogpile.cache is a next generation replacement for Beaker made by the same authors. ### Search _Libraries and software for indexing and performing search queries on data._ -- [elasticsearch](https://github.com/elastic/elasticsearch-py) - The official low-level Python client for [Elasticsearch](https://www.elastic.co/elasticsearch). - [opensearch-py](https://github.com/opensearch-project/opensearch-py) - The official low-level Python client for [OpenSearch](https://opensearch.org/). +- [elasticsearch](https://github.com/elastic/elasticsearch-py) - The official low-level Python client for [Elasticsearch](https://www.elastic.co/elasticsearch). - [meilisearch](https://github.com/meilisearch/meilisearch-python) - The official Python client for the [Meilisearch](https://www.meilisearch.com/) search engine. - [django-haystack](https://github.com/django-haystack/django-haystack) - Modular search for Django. From 9af92c2582a42f67fef775638c34d44daffd417a Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:40:29 +0800 Subject: [PATCH 14/50] audit: sweep Data Ingestion / ETL, drop pathway Removed: pathway (8,449 downloads/month, pypistats 2026-10-02): not open source (Business Source License, converting to Apache 2.0 only after four years, with a cloud-resale ban) and flat downloads, so no adoption trajectory for a challenger slot. Also: openbb's link moves to github.com/openbq-org/OpenBB, where OpenBB-finance/OpenBB now redirects after the company's wind-down handed the code to the non-profit OpenBQ. Co-Authored-By: Claude --- README.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/README.md b/README.md index b398cf2e..45ff1768 100644 --- a/README.md +++ b/README.md @@ -510,12 +510,11 @@ _Libraries for data extraction, transformation, and loading pipelines across mul - General - [awswrangler](https://github.com/aws/aws-sdk-pandas) - Pandas integration with AWS services like Athena, Glue, Redshift, S3, and DynamoDB. - [dlt](https://github.com/dlt-hub/dlt) - A Python library for building data pipelines with automatic schema inference, incremental loading, and support for multiple sources and destinations. - - [pathway](https://github.com/pathwaycom/pathway) - Python ETL framework for stream processing, real-time analytics, LLM pipelines, and RAG. - Financial Data - [yfinance](https://github.com/ranaroussi/yfinance) - Easy Pythonic way to download market and financial data from Yahoo Finance. - [akshare](https://github.com/akfamily/akshare) - A financial data interface library, with data provided for academic research only. - [edgartools](https://github.com/dgunning/edgartools) - Library for downloading structured data from SEC EDGAR filings and XBRL financial statements. - - [openbb](https://github.com/OpenBB-finance/OpenBB) - A financial data platform for analysts, quants and AI agents. + - [openbb](https://github.com/openbq-org/OpenBB) - A financial data platform for analysts, quants and AI agents. ### Data Validation From 8144f6b56d7bbbfa68ed93fe7abd5cd18c14161d Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:40:41 +0800 Subject: [PATCH 15/50] audit: sweep Data Visualization, replace pygraphviz with graphviz Removed: pygraphviz (528,553 downloads/month, pypistats 2026-10-02): displaced by graphviz (32,829,050/month, part of it catboost pulling it in), which does the same job of building and rendering Graphviz graphs as pure Python with no C build. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 45ff1768..a8664892 100644 --- a/README.md +++ b/README.md @@ -535,8 +535,8 @@ _Libraries for visualizing data. Also see [awesome-javascript](https://github.co - [altair](https://github.com/vega/altair) - Declarative statistical visualization library for Python. - [bokeh](https://github.com/bokeh/bokeh) - Interactive Web Plotting for Python. - Specialized + - [graphviz](https://github.com/xflr6/graphviz) - Simple Python interface for creating and rendering Graphviz graphs. - [cartopy](https://github.com/SciTools/cartopy) - A cartographic python library with matplotlib support. - - [pygraphviz](https://github.com/pygraphviz/pygraphviz/) - Python interface to [Graphviz](https://www.graphviz.org/). - [graphify](https://github.com/Graphify-Labs/graphify) - Turn any folder of code, SQL schemas, docs, papers, images, or videos into a queryable knowledge graph. - Dashboards and Apps - [streamlit](https://github.com/streamlit/streamlit) - A framework which lets you build dashboards, generate reports, or create chat apps in minutes. From 7254ab543b10ad803751e9867aaa91bcf46a3502 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:40:53 +0800 Subject: [PATCH 16/50] feat: add dash to Data Visualization > Dashboards and Apps Dashboards and Apps omitted Plotly's dash, which outdraws the listed gradio (6,253,566 vs 5,227,393 downloads/month, pypistats 2026-10-02). Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index a8664892..aa889719 100644 --- a/README.md +++ b/README.md @@ -540,6 +540,7 @@ _Libraries for visualizing data. Also see [awesome-javascript](https://github.co - [graphify](https://github.com/Graphify-Labs/graphify) - Turn any folder of code, SQL schemas, docs, papers, images, or videos into a queryable knowledge graph. - Dashboards and Apps - [streamlit](https://github.com/streamlit/streamlit) - A framework which lets you build dashboards, generate reports, or create chat apps in minutes. + - [dash](https://github.com/plotly/dash) - A framework for building data apps and dashboards in pure Python, built on Plotly. - [gradio](https://github.com/gradio-app/gradio) - Build and share machine learning apps, all in Python. ### Geolocation From 804991ef7990e879030f13fa2f6a6b6220edf16a Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:41:04 +0800 Subject: [PATCH 17/50] feat: add great-expectations to Data Validation Data Validation omitted great-expectations, the most-installed data quality framework at 19,340,380 downloads/month (pypistats 2026-10-02), more than twice pandera's 8,170,879; the audit left it out only because it requires Python <3.14, which the Python-version rule no longer treats as grounds for exclusion. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index aa889719..4819b9ac 100644 --- a/README.md +++ b/README.md @@ -522,6 +522,7 @@ _Libraries for validating data. Used for forms in many cases._ - [pydantic](https://github.com/pydantic/pydantic) - Data validation using Python type hints. - [jsonschema](https://github.com/python-jsonschema/jsonschema) - An implementation of [JSON Schema](https://json-schema.org/) for Python. +- [great-expectations](https://github.com/fivetran/great_expectations) - A data quality framework for validating, documenting, and profiling data with declarative expectations. - [pandera](https://github.com/unionai-oss/pandera) - A data validation library for dataframes, with support for pandas, polars, PySpark, and more. ### Data Visualization From d637af7cb4cedcbf1de75fd7e993fd090575771b Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:41:15 +0800 Subject: [PATCH 18/50] style: reorder Science > Biology and Chemistry by downloads biopython sat above rdkit although rdkit now has more downloads (ClickPy 2026-10-01), against the downloads-order rule. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 4819b9ac..b9f1d1e2 100644 --- a/README.md +++ b/README.md @@ -566,8 +566,8 @@ _Libraries for scientific computing. Also see [Python-for-Scientists](https://gi - Statistics - [statsmodels](https://github.com/statsmodels/statsmodels) - Statistical modeling and econometrics in Python. - Biology and Chemistry - - [biopython](https://github.com/biopython/biopython) - Biopython is a set of freely available tools for biological computation. - [rdkit](https://github.com/rdkit/rdkit) - Cheminformatics and Machine Learning Software. + - [biopython](https://github.com/biopython/biopython) - Biopython is a set of freely available tools for biological computation. - Physics and Engineering - [pint](https://github.com/hgrecco/pint) - Operate and manipulate physical quantities with units and dimensional analysis. - [astropy](https://github.com/astropy/astropy) - A community Python library for Astronomy. From d9b6d6a0bccda18d64085b95707a30691056f35e Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:41:34 +0800 Subject: [PATCH 19/50] audit: sweep Algorithms and Design Patterns, drop transitions Removed: transitions (2,483,235 downloads/month, pypistats 2026-10-02): fails the 12-month activity line (last commit 2025-09-09, last release 2025-07-02), and python-statemachine (1,430,000-plus/month, released 3.2.1 on 2026-08-01) is an active successor for the same job, so it does not qualify as a mature-stable keep. Co-Authored-By: Claude --- README.md | 1 - 1 file changed, 1 deletion(-) diff --git a/README.md b/README.md index b9f1d1e2..802337cf 100644 --- a/README.md +++ b/README.md @@ -604,7 +604,6 @@ _Python implementation of data structures, algorithms and design patterns. Also - [algorithms](https://github.com/keon/algorithms) - Minimal examples of data structures and algorithms. - [thealgorithms](https://github.com/TheAlgorithms/Python) - All Algorithms implemented in Python. - Design Patterns - - [transitions](https://github.com/pytransitions/transitions) - A lightweight, object-oriented finite state machine implementation. - [python-patterns](https://github.com/faif/python-patterns) - A collection of design patterns in Python. - [python-statemachine](https://github.com/fgmacedo/python-statemachine) - Expressive statecharts and finite state machines with a declarative API, in sync and async codebases. From c45f3f81d256339b56e9beec323a556b3358d314 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:41:48 +0800 Subject: [PATCH 20/50] audit: sweep Code Analysis, drop repowise, monkeytype Removed: repowise (14,584 downloads/month, pypistats 2026-10-02): no adoption trajectory (about 33K in August to 19.5K on ClickPy), and it left Code Analysis with three challengers against a limit of two. monkeytype (529,705/month): fails the 12-month activity line (default branch last commit 2025-06-14, last release 2023-03-20). Dropping monkeytype empties Type Annotations Generators, so the subcategory is dissolved and its URL redirects to /categories/code-analysis/. Co-Authored-By: Claude --- README.md | 3 --- website/data/redirects.json | 1 + 2 files changed, 1 insertion(+), 3 deletions(-) diff --git a/README.md b/README.md index 802337cf..0f9ff701 100644 --- a/README.md +++ b/README.md @@ -626,7 +626,6 @@ _Tools of static analysis, linters and code quality checkers. Also see [awesome- - [vulture](https://github.com/jendrikseipp/vulture) - A tool for finding and analyzing dead Python code. - [complexipy](https://github.com/rohaquinlop/complexipy) - Cognitive complexity analysis for Python code, written in Rust. - [prospector](https://github.com/prospector-dev/prospector) - A tool to analyze Python code. - - [repowise](https://github.com/repowise-dev/repowise) - Codebase intelligence that indexes repos into dependency graphs, git history, and auto-generated docs with dead code detection. - Git Hooks - [pre-commit](https://github.com/pre-commit/pre-commit) - A framework for managing and maintaining multi-language pre-commit hooks. - Linters and Formatters @@ -644,8 +643,6 @@ _Tools of static analysis, linters and code quality checkers. Also see [awesome- - [ty](https://github.com/astral-sh/ty) - An extremely fast Python type checker and language server. - [pyright](https://github.com/microsoft/pyright) - Full-featured static type checker for Python from Microsoft, the engine behind Pylance. - [pyrefly](https://github.com/facebook/pyrefly) - A fast type checker and language server for Python. -- Type Annotations Generators - - [monkeytype](https://github.com/Instagram/MonkeyType) - A system for Python that generates static type annotations by collecting runtime types. ### Testing diff --git a/website/data/redirects.json b/website/data/redirects.json index af60550e..28070c20 100644 --- a/website/data/redirects.json +++ b/website/data/redirects.json @@ -3,6 +3,7 @@ "/categories/ai-and-agents/pre-trained-models-and-inference/": "/categories/ai-and-agents/pre-trained-models/", "/categories/cli-tools/productivity-tools/": "/categories/cli-tools/", "/categories/code-analysis/code-linters/": "/categories/code-analysis/linters-and-formatters/", + "/categories/code-analysis/type-annotations-generators/": "/categories/code-analysis/", "/categories/data-analysis/financial-data/": "/categories/data-ingestion-etl/financial-data/", "/categories/distributed-computing/batch-processing/": "/categories/distributed-computing/", "/categories/gui-development/terminal/": "/categories/cli-development/tui-frameworks/", From 1627cfda21540a6ba3509e7214dd5700dfe04b89 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:42:03 +0800 Subject: [PATCH 21/50] audit: sweep Testing, replace freezegun with time-machine Removed: freezegun (45,539,075 downloads/month, pypistats 2026-10-02): fails the 12-month activity line (last commit 2025-08-19, last release 2025-08-09), and time-machine (18,960,236/month, released 3.5.1 on 2026-09-08) is an active successor for the same job that ships a freezegun migration tool, so freezegun does not qualify as a mature-stable keep. time-machine takes the slot as a challenger, last in Mock. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 0f9ff701..847e148f 100644 --- a/README.md +++ b/README.md @@ -667,9 +667,9 @@ _Libraries for testing codebases and generating test data. Also see [awesome-pyt - Mock - [mock](https://docs.python.org/3/library/unittest.mock.html) - (Python standard library) A mocking and patching library. - [responses](https://github.com/getsentry/responses) - A utility library for mocking out the requests Python library. - - [freezegun](https://github.com/spulec/freezegun) - Travel through time by mocking the datetime module. - [vcrpy](https://github.com/kevin1024/vcrpy) - Record and replay HTTP interactions on your tests. - [respx](https://github.com/lundberg/respx) - Mock HTTPX with awesome request patterns and response side effects. + - [time-machine](https://github.com/adamchainz/time-machine) - Travel through time in your tests by mocking the current time at the C level. - Object Factories - [factory_boy](https://github.com/FactoryBoy/factory_boy) - A test fixtures replacement for Python. - [polyfactory](https://github.com/litestar-org/polyfactory) - A mock data generation library based on type hints (continuation of `pydantic-factories`). From 9a264098815d7ce9dd2a565e572d43e905bb045f Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:42:15 +0800 Subject: [PATCH 22/50] audit: sweep Debugging Tools, replace hunter with viztracer Removed: hunter (782,874 downloads/month, pypistats 2026-10-02): fails the 12-month activity line (last commit and release 3.9.0 on 2025-08-22). viztracer (1,173,045/month on the same source, pushed 2026-09-26) takes the Tracing slot. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 847e148f..ddda74ef 100644 --- a/README.md +++ b/README.md @@ -687,7 +687,7 @@ _Libraries for debugging code._ - [ipdb](https://github.com/gotcha/ipdb) - IPython-enabled [pdb](https://docs.python.org/3/library/pdb.html). - [pudb](https://github.com/inducer/pudb) - A full-screen, console-based Python debugger. - Tracing - - [hunter](https://github.com/ionelmc/python-hunter) - A flexible code tracing toolkit. + - [viztracer](https://github.com/gaogaotiantian/viztracer) - A low-overhead tool that traces and visualizes Python code execution. - Profiler - [py-spy](https://github.com/benfred/py-spy) - A sampling profiler for Python programs. Written in Rust. - [memray](https://github.com/bloomberg/memray) - A memory profiler that tracks allocations in Python code, native extensions, and the interpreter itself. From e4bd305ad987782b06fd75611756ac76f1a4dc0c Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:42:26 +0800 Subject: [PATCH 23/50] feat: add poethepoet to Build Tools Build Tools had no pyproject.toml task runner for poetry or uv projects. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index ddda74ef..8b1c4849 100644 --- a/README.md +++ b/README.md @@ -703,6 +703,7 @@ _Libraries for debugging code._ _Task runners and software build tools. If you're looking for Python packaging/build tools, see [Package Management](#package-management)._ - [invoke](https://github.com/pyinvoke/invoke) - A tool for managing shell-oriented subprocesses and organizing executable Python code into CLI-invokable tasks. +- [poethepoet](https://github.com/nat-n/poethepoet) - A task runner that defines tasks in pyproject.toml and works with poetry or uv. - [scons](https://github.com/SCons/scons) - A software construction tool. - [doit](https://github.com/pydoit/doit) - A task runner and build tool. From 84b5508561269ca51abc23e16496b6f5c1af00db Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:42:47 +0800 Subject: [PATCH 24/50] audit: sweep DevOps Tools, drop chaostoolkit Removed: chaostoolkit (11,525 downloads/month, ClickPy 2026-10-01): no adoption-trajectory evidence and falling (about 18K in August); active, so the drop is editorial. Also: awscli's line now says the PyPI package is CLI v1, which entered maintenance mode on 2026-07-15 (end of support 2027-07-15), while v2 ships only as AWS's bundled installer. Co-Authored-By: Claude --- README.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/README.md b/README.md index 8b1c4849..8f2d80cf 100644 --- a/README.md +++ b/README.md @@ -726,7 +726,7 @@ _Software and libraries for DevOps._ - Cloud Providers - [boto3](https://github.com/boto/boto3) - Python interface to Amazon Web Services. - - [awscli](https://github.com/aws/aws-cli) - Universal Command Line Interface for Amazon Web Services. + - [awscli](https://github.com/aws/aws-cli) - Universal Command Line Interface for Amazon Web Services; the PyPI package is v1, in maintenance mode, while v2 ships as AWS's bundled installer. - [azure-sdk-for-python](https://github.com/Azure/azure-sdk-for-python) - Microsoft Azure SDK for Python, published as per-service packages. - [google-cloud-python](https://github.com/googleapis/google-cloud-python) - Google Cloud client libraries for Python, published as per-service packages. - Configuration Management @@ -745,7 +745,6 @@ _Software and libraries for DevOps._ - [sh](https://github.com/amoffat/sh) - A full-fledged subprocess replacement for Python. - Other - [borgbackup](https://github.com/borgbackup/borg) - A deduplicating archiver with compression and encryption. - - [chaostoolkit](https://github.com/chaostoolkit/chaostoolkit) - A Chaos Engineering toolkit & Orchestration for Developers. ### Distributed Computing From d2065fbf80ed62d376c276bb3106bdbabf66a6b2 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:43:00 +0800 Subject: [PATCH 25/50] style: audit DevOps ordering and Network Virtualization description Distributed Computing listed ray first though pyspark and dask now outdraw it, Workflow Orchestration listed apache-airflow and prefect above dagster, which now leads on downloads, and the Network Virtualization description fit neither scapy nor napalm. Co-Authored-By: Claude --- README.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 8f2d80cf..2120a889 100644 --- a/README.md +++ b/README.md @@ -750,9 +750,9 @@ _Software and libraries for DevOps._ _Frameworks and libraries for Distributed Computing._ -- [ray](https://github.com/ray-project/ray/) - A unified framework for scaling AI and Python applications. - [pyspark](https://github.com/apache/spark) - [Apache Spark](https://spark.apache.org/) Python API. - [dask](https://github.com/dask/dask) - A flexible parallel computing library for analytic computing. +- [ray](https://github.com/ray-project/ray/) - A unified framework for scaling AI and Python applications. - [joblib](https://github.com/joblib/joblib) - Parallel computing and disk-based caching for Python functions. - [mpi4py](https://github.com/mpi4py/mpi4py) - Python bindings for MPI. @@ -783,9 +783,9 @@ _Libraries for scheduling jobs._ - [apscheduler](https://github.com/agronholm/apscheduler) - A light but powerful in-process task scheduler that lets you schedule functions. - [schedule](https://github.com/dbader/schedule) - Python job scheduling for humans. - Workflow Orchestration + - [dagster](https://github.com/dagster-io/dagster) - An orchestration platform for the development, production, and observation of data assets. - [apache-airflow](https://github.com/apache/airflow) - Airflow is a platform to programmatically author, schedule and monitor workflows. - [prefect](https://github.com/PrefectHQ/prefect) - A modern workflow orchestration framework that makes it easy to build, schedule and monitor robust data pipelines. - - [dagster](https://github.com/dagster-io/dagster) - An orchestration platform for the development, production, and observation of data assets. ### Logging @@ -798,7 +798,7 @@ _Libraries for generating and working with logs._ ### Network Virtualization -_Tools and libraries for Virtual Networking and SDN (Software Defined Networking)._ +_Tools and libraries for packet manipulation and network device automation._ - [scapy](https://github.com/secdev/scapy) - A brilliant packet manipulation library. - [napalm](https://github.com/napalm-automation/napalm) - Cross-vendor API to manipulate network devices. From 8ae9b1957bbe46447f9fb05478eedf55d284d04c Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:43:10 +0800 Subject: [PATCH 26/50] feat: add netmiko to Network Virtualization Network Virtualization lacked netmiko, the standard Python library for SSH network-device automation, though most of its downloads are standalone rather than pulled in by napalm. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 2120a889..46f48bc9 100644 --- a/README.md +++ b/README.md @@ -801,6 +801,7 @@ _Libraries for generating and working with logs._ _Tools and libraries for packet manipulation and network device automation._ - [scapy](https://github.com/secdev/scapy) - A brilliant packet manipulation library. +- [netmiko](https://github.com/ktbyers/netmiko) - Multi-vendor library to simplify CLI connections to network devices. - [napalm](https://github.com/napalm-automation/napalm) - Cross-vendor API to manipulate network devices. **CLI & GUI** From 9d718813d1f8c08a54e5c27140b1c848e8b3b8af Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:43:24 +0800 Subject: [PATCH 27/50] style: reorder CLI Development > Terminal Rendering by downloads tqdm sat above rich although rich has more downloads. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 46f48bc9..f7e2b965 100644 --- a/README.md +++ b/README.md @@ -817,8 +817,8 @@ _Libraries for building command-line applications._ - [prompt_toolkit](https://github.com/prompt-toolkit/python-prompt-toolkit) - A library for building powerful interactive command lines. - [fire](https://github.com/google/python-fire) - A library for creating command line interfaces from absolutely any Python object. - Terminal Rendering - - [tqdm](https://github.com/tqdm/tqdm) - Fast, extensible progress bar for loops and CLI. - [rich](https://github.com/Textualize/rich) - Python library for rich text and beautiful formatting in the terminal. Also provides a great `RichHandler` log handler. + - [tqdm](https://github.com/tqdm/tqdm) - Fast, extensible progress bar for loops and CLI. - [colorama](https://github.com/tartley/colorama) - Cross-platform colored terminal text. - [alive-progress](https://github.com/rsalmei/alive-progress) - A new kind of Progress Bar, with real-time throughput, eta and very cool animations. - TUI Frameworks From c0fdb40ee4ed313f3ae39da7b59eda3bf041398f Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:43:40 +0800 Subject: [PATCH 28/50] audit: sweep GUI Development, drop tkdesigner, gooey Removed: tkdesigner (317 downloads/month, ClickPy 2026-10-01): its only PyPI release, 1.0.7 (2023-01-22), pins Pillow<9, requests==2.25.1 and urllib3<2, so it has no installable wheels on Python 3.11+, which reverses the August keep. gooey (6,049/month): no release since 1.0.8.1 on 2021-06-12. Dropping gooey empties Wrappers, so the subcategory is dissolved and its URL redirects to /categories/gui-development/. Also: Desktop re-tier, dearpygui up to obvious choice (the only Desktop entry that grew since August) and wxPython down to Second Tier (about half its August downloads). Co-Authored-By: Claude --- README.md | 7 ++----- website/data/redirects.json | 1 + 2 files changed, 3 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index f7e2b965..0ec91efc 100644 --- a/README.md +++ b/README.md @@ -853,9 +853,9 @@ _Libraries for working with graphical user interface applications._ - Desktop - [pygobject](https://github.com/GNOME/pygobject) - Python Bindings for GLib/GObject/GIO/GTK. - - [wxPython](https://github.com/wxWidgets/Phoenix) - A cross-platform GUI toolkit that wraps the wxWidgets C++ library. - - [kivy](https://github.com/kivy/kivy) - An open-source framework for cross-platform GUI apps on desktop, mobile, and embedded platforms. - [dearpygui](https://github.com/hoffstadt/DearPyGui) - A simple GPU-accelerated Python GUI framework. + - [kivy](https://github.com/kivy/kivy) - An open-source framework for cross-platform GUI apps on desktop, mobile, and embedded platforms. + - [wxPython](https://github.com/wxWidgets/Phoenix) - A cross-platform GUI toolkit that wraps the wxWidgets C++ library. - [toga](https://github.com/beeware/toga) - A Python native, OS native GUI toolkit. - Qt - [PySide6](https://github.com/pyside/pyside-setup) - Qt for Python offers the official Python bindings for [Qt](https://www.qt.io/), largely API-compatible with PyQt6 but with different licensing. @@ -863,13 +863,10 @@ _Libraries for working with graphical user interface applications._ - Tkinter - [tkinter](https://docs.python.org/3/library/tkinter.html) - (Python standard library) The standard Python interface to the Tcl/Tk GUI toolkit. - [customtkinter](https://github.com/tomschimansky/customtkinter) - A modern and customizable python UI-library based on Tkinter. - - [tkdesigner](https://github.com/ParthJadhav/Tkinter-Designer) - Generates Tkinter interfaces from Figma designs using the Figma API. - Web-based - [pywebview](https://github.com/r0x0r/pywebview/) - A lightweight cross-platform native wrapper around a webview component. - [nicegui](https://github.com/zauberzeug/nicegui) - An easy-to-use, Python-based UI framework, which shows up in your web browser. - [flet](https://github.com/flet-dev/flet) - Cross-platform GUI framework for building modern apps in pure Python. -- Wrappers - - [gooey](https://github.com/chriskiehl/Gooey) - Turn command line programs into a full GUI application with one line. **Text & Documents** diff --git a/website/data/redirects.json b/website/data/redirects.json index 28070c20..0518fdc4 100644 --- a/website/data/redirects.json +++ b/website/data/redirects.json @@ -7,5 +7,6 @@ "/categories/data-analysis/financial-data/": "/categories/data-ingestion-etl/financial-data/", "/categories/distributed-computing/batch-processing/": "/categories/distributed-computing/", "/categories/gui-development/terminal/": "/categories/cli-development/tui-frameworks/", + "/categories/gui-development/wrappers/": "/categories/gui-development/", "/categories/web-servers/rpc/": "/categories/web-apis/rpc/" } From c58446c50ab1bab2c551b06e49911868a2874b1d Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:43:57 +0800 Subject: [PATCH 29/50] audit: sweep Text Processing, drop sqids Removed: sqids (537,334 downloads/month, pypistats 2026-10-02): fails the 12-month activity line (last commit 2025-03-26, last release 2025-05-13), and its predecessor hashids still draws about 4x its downloads, so there is no successor trajectory to justify a challenger slot. Co-Authored-By: Claude --- README.md | 1 - 1 file changed, 1 deletion(-) diff --git a/README.md b/README.md index 0ec91efc..f652f0f8 100644 --- a/README.md +++ b/README.md @@ -896,7 +896,6 @@ _Libraries for parsing and manipulating plain texts._ - [unidecode](https://github.com/avian2/unidecode) - ASCII transliterations of Unicode text. - Unique identifiers - [shortuuid](https://github.com/skorokithakis/shortuuid) - A generator library for concise, unambiguous and URL-safe UUIDs. - - [sqids](https://github.com/sqids/sqids-python) - A library for generating short unique IDs from numbers. ### HTML Manipulation From ec527e931681e841fbd0acc82f1b38d634bfa6df Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:44:08 +0800 Subject: [PATCH 30/50] style: reorder HTML Manipulation and fix the ReportLab link beautifulsoup4 sat above lxml although lxml now has more monthly downloads (313.9M vs 297.1M), and the reportlab link redirected to the docs site. Co-Authored-By: Claude --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index f652f0f8..6558571c 100644 --- a/README.md +++ b/README.md @@ -901,8 +901,8 @@ _Libraries for parsing and manipulating plain texts._ _Libraries for working with HTML and XML._ -- [beautifulsoup4](https://www.crummy.com/software/BeautifulSoup/bs4/doc/) - Providing Pythonic idioms for iterating, searching, and modifying HTML or XML. - [lxml](https://github.com/lxml/lxml) - A very fast, easy-to-use and versatile library for handling HTML and XML. +- [beautifulsoup4](https://www.crummy.com/software/BeautifulSoup/bs4/doc/) - Providing Pythonic idioms for iterating, searching, and modifying HTML or XML. - [xmltodict](https://github.com/martinblech/xmltodict) - Working with XML feel like you are working with JSON. - [markupsafe](https://github.com/pallets/markupsafe) - Safely adds untrusted strings to HTML/XML markup. - [justhtml](https://github.com/EmilStenstrom/justhtml/) - A pure Python HTML5 parser that sanitizes untrusted HTML by default. @@ -926,7 +926,7 @@ _Libraries for parsing and manipulating specific file formats._ - [python-pptx](https://github.com/scanny/python-pptx) - Python library for creating and updating PowerPoint (.pptx) files. - PDF - [pypdf](https://github.com/py-pdf/pypdf) - A library capable of splitting, merging, cropping, and transforming PDF pages. - - [reportlab](https://www.reportlab.com/opensource/) - Allowing Rapid creation of rich PDF documents. + - [reportlab](https://docs.reportlab.com/) - Allowing Rapid creation of rich PDF documents. - [pdfminer.six](https://github.com/pdfminer/pdfminer.six) - A community-maintained fork of PDFMiner for extracting information from PDF documents. - HTML-to-PDF - [weasyprint](https://github.com/Kozea/WeasyPrint) - A visual rendering engine for HTML and CSS that can export to PDF. From 7674d5d0b46f7baa1b07aaa4f00d3c846669c029 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:44:22 +0800 Subject: [PATCH 31/50] feat: add pymupdf to File Format Processing > PDF PDF omitted pymupdf, the second most-installed PDF library at 81,101,392 downloads/month (pypistats 2026-10-02) and the fastest at text extraction and page rendering. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 6558571c..e74b591a 100644 --- a/README.md +++ b/README.md @@ -926,6 +926,7 @@ _Libraries for parsing and manipulating specific file formats._ - [python-pptx](https://github.com/scanny/python-pptx) - Python library for creating and updating PowerPoint (.pptx) files. - PDF - [pypdf](https://github.com/py-pdf/pypdf) - A library capable of splitting, merging, cropping, and transforming PDF pages. + - [pymupdf](https://github.com/pymupdf/PyMuPDF) - A fast library for extracting, rendering, and editing PDF and other document formats, built on MuPDF. - [reportlab](https://docs.reportlab.com/) - Allowing Rapid creation of rich PDF documents. - [pdfminer.six](https://github.com/pdfminer/pdfminer.six) - A community-maintained fork of PDFMiner for extracting information from PDF documents. - HTML-to-PDF From 1d23e7b02216ff2ab45e4ecb34cf638f6d583c09 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:44:40 +0800 Subject: [PATCH 32/50] audit: sweep Audio & Video Processing, drop vidgear Removed: vidgear (10,854 downloads/month, pypistats 2026-10-02): a challenger with no adoption trajectory (about half its August count), not anyone's unprompted answer next to moviepy and PyAV. Also: pydub moves below librosa to Second Tier under the Python-version rule; its only release, 0.25.1 (2021), fails `import pydub` on Python 3.13+ without audioop-lts, but it still has 17,778,797 downloads/month. Co-Authored-By: Claude --- README.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/README.md b/README.md index e74b591a..c18bab8c 100644 --- a/README.md +++ b/README.md @@ -972,11 +972,10 @@ _Libraries for manipulating images._ _Libraries for manipulating audio, video, and their metadata._ - Audio - - [pydub](https://github.com/jiaaro/pydub) - Manipulate audio with a simple and easy high level interface. - [librosa](https://github.com/librosa/librosa) - Python library for audio and music analysis. + - [pydub](https://github.com/jiaaro/pydub) - Manipulate audio with a simple and easy high level interface. - Video - [moviepy](https://github.com/Zulko/moviepy) - A module for script-based movie editing with many formats, including animated GIFs. - - [vidgear](https://github.com/abhiTronix/vidgear) - A high-performance, cross-platform, multi-threaded video processing framework. - Metadata - [mutagen](https://github.com/quodlibet/mutagen) - A Python module to handle audio metadata. - [tinytag](https://github.com/tinytag/tinytag) - A library for reading audio file metadata of MP3, MP4, WAV, OGG, FLAC, WMA, and AIFF files. From f6698bd110a1a184a31602cc5f22947ec302085b Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:44:51 +0800 Subject: [PATCH 33/50] feat: add soundfile to Audio & Video Processing > Audio Audio listed no general audio file I/O library, though soundfile is the standard libsndfile reader and writer under librosa. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index c18bab8c..8056d77f 100644 --- a/README.md +++ b/README.md @@ -972,6 +972,7 @@ _Libraries for manipulating images._ _Libraries for manipulating audio, video, and their metadata._ - Audio + - [soundfile](https://github.com/bastibe/python-soundfile) - An audio library for reading and writing sound files, based on libsndfile, CFFI, and NumPy. - [librosa](https://github.com/librosa/librosa) - Python library for audio and music analysis. - [pydub](https://github.com/jiaaro/pydub) - Manipulate audio with a simple and easy high level interface. - Video From b5070b2841041e3ce0d07bed70edbdae933da281 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:45:02 +0800 Subject: [PATCH 34/50] feat: add av to Audio & Video Processing > Video Video had no direct way to decode, encode, and mux video from Python. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 8056d77f..3b6d7433 100644 --- a/README.md +++ b/README.md @@ -976,6 +976,7 @@ _Libraries for manipulating audio, video, and their metadata._ - [librosa](https://github.com/librosa/librosa) - Python library for audio and music analysis. - [pydub](https://github.com/jiaaro/pydub) - Manipulate audio with a simple and easy high level interface. - Video + - [av](https://github.com/PyAV-Org/PyAV) - Pythonic bindings for FFmpeg's libraries. - [moviepy](https://github.com/Zulko/moviepy) - A module for script-based movie editing with many formats, including animated GIFs. - Metadata - [mutagen](https://github.com/quodlibet/mutagen) - A Python module to handle audio metadata. From f05edd8d07d845764ba3b1cc78023282a7515987 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:45:14 +0800 Subject: [PATCH 35/50] audit: sweep Game Development, promote pygame-ce over pygame pygame led Game Frameworks although its last release, 2.6.1, has no Python 3.14 wheel and the source build fails, while the actively developed drop-in replacement pygame-ce sat below it. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 3b6d7433..8e118e29 100644 --- a/README.md +++ b/README.md @@ -990,9 +990,9 @@ _Awesome game development libraries._ - 3D Engines - [panda3d](https://github.com/panda3d/panda3d) - 3D game engine developed jointly by Disney and contributors from around the world. - Game Frameworks - - [pygame](https://github.com/pygame/pygame) - Pygame is a set of Python modules designed for writing games. - [pyglet](https://github.com/pyglet/pyglet) - A cross-platform windowing and multimedia library for Python. - [pygame-ce](https://github.com/pygame-community/pygame-ce) - An actively developed drop-in replacement with new features and performance improvements ([pygame](https://github.com/pygame/pygame) fork). + - [pygame](https://github.com/pygame/pygame) - Pygame is a set of Python modules designed for writing games. - [arcade](https://github.com/pythonarcade/arcade) - Arcade is a modern Python framework for crafting games with compelling graphics and sound. - Visual Novels - [renpy](https://github.com/renpy/renpy) - A Visual Novel engine. From ebc178d6e099383a9de4da1e556c311c114d1852 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:45:26 +0800 Subject: [PATCH 36/50] docs: drop the RFC 9562 claim from uuid-utils The uuid-utils line set it apart by RFC 9562 support (UUIDv6, v7, v8), but the standard library uuid module gained uuid6, uuid7 and uuid8 in Python 3.14, so that no longer distinguishes it. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 8e118e29..f6e812e9 100644 --- a/README.md +++ b/README.md @@ -1015,7 +1015,7 @@ _Libraries for enhancing Python built-in classes._ - [attrs](https://github.com/python-attrs/attrs) - Replacement for `__init__`, `__eq__`, `__repr__`, etc. boilerplate in class definitions. - [bidict](https://github.com/jab/bidict) - Efficient, Pythonic bidirectional map data structures and related functionality. -- [uuid-utils](https://github.com/aminalaee/uuid-utils) - A fast, Rust-backed drop-in replacement for Python's built-in `uuid` module, supporting RFC 9562 (UUIDv6, UUIDv7, and UUIDv8). +- [uuid-utils](https://github.com/aminalaee/uuid-utils) - A fast, Rust-backed drop-in replacement for Python's built-in `uuid` module. - [python-box](https://github.com/cdgriffith/Box) - Python dictionaries with advanced dot notation access. ### Functional Programming From ddaa697e988a1a5eff539a1a2f41de63b0c14677 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:45:53 +0800 Subject: [PATCH 37/50] audit: sweep Package Repositories, drop warehouse Removed: warehouse (no PyPI download signal; not a pip-installed package): the section is self-hosted servers, proxies, and mirrors, and Warehouse is not one. Its docs call pypi.org the canonical deployment and document only a local development setup, and the PyPA guide to hosting your own repository does not list it. Also: devpi (99,216 downloads/month for devpi-server, pypistats 2026-10-02) moves above bandersnatch (4,351) to follow the downloads order. Co-Authored-By: Claude --- README.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/README.md b/README.md index f6e812e9..09f7ffc3 100644 --- a/README.md +++ b/README.md @@ -1084,9 +1084,8 @@ _Libraries for package and dependency management._ _Local PyPI repository servers, proxies, and mirrors._ -- [bandersnatch](https://github.com/pypa/bandersnatch/) - PyPI mirroring tool provided by Python Packaging Authority (PyPA). - [devpi](https://github.com/devpi/devpi) - PyPI server and packaging/testing/release tool. -- [warehouse](https://github.com/pypi/warehouse) - The software that powers PyPI. +- [bandersnatch](https://github.com/pypa/bandersnatch/) - PyPI mirroring tool provided by Python Packaging Authority (PyPA). ### Distribution From 3d229e74573ecbd17a1f1abc7db078dc76bea512 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:46:05 +0800 Subject: [PATCH 38/50] feat: add pypiserver to Package Repositories Package Repositories omitted pypiserver, the minimal self-hosted index the PyPA hosting guide names alongside devpi, which has 5x the downloads of devpi-server. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 09f7ffc3..5bdd7573 100644 --- a/README.md +++ b/README.md @@ -1084,6 +1084,7 @@ _Libraries for package and dependency management._ _Local PyPI repository servers, proxies, and mirrors._ +- [pypiserver](https://github.com/pypiserver/pypiserver) - A minimal PyPI server for uploading and installing packages with pip. - [devpi](https://github.com/devpi/devpi) - PyPI server and packaging/testing/release tool. - [bandersnatch](https://github.com/pypa/bandersnatch/) - PyPI mirroring tool provided by Python Packaging Authority (PyPA). From 607415e3c603d341ea73829b4db14636dd5be147 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:46:17 +0800 Subject: [PATCH 39/50] feat: add poetry-core to Package Management > Build Backends Build Backends omitted poetry-core, the backend of every Poetry project, at 88,000,485 downloads/month; about 47M remains without poetry, still 3x uv-build. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 5bdd7573..2c15b222 100644 --- a/README.md +++ b/README.md @@ -1078,6 +1078,7 @@ _Libraries for package and dependency management._ - Build Backends - [setuptools](https://github.com/pypa/setuptools) - The historical and still most widely used pyproject build backend. - [hatchling](https://github.com/pypa/hatch) - Modern, extensible build backend from the hatch project. + - [poetry-core](https://github.com/python-poetry/poetry-core) - Poetry's PEP 517 build backend, usable without Poetry itself. - [uv-build](https://github.com/astral-sh/uv) - uv's fast, minimal build backend for pure-Python projects. ### Package Repositories From ddf118cf77d373b2e136b56295a1d16b313a86d9 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:46:27 +0800 Subject: [PATCH 40/50] audit: sweep Distribution, replace shiv with pex Removed: shiv (224,563 downloads/month, pypistats 2026-10-02): displaced by pex (4,682,918/month on the same source, released 2026-10-02), the more-used and more-active builder for the same self-contained zipapp job; shiv's last release was 1.0.8 on 2024-11-01. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 2c15b222..747143c4 100644 --- a/README.md +++ b/README.md @@ -1096,7 +1096,7 @@ _Libraries to create packaged executables for release distribution._ - Executables - [pyinstaller](https://github.com/pyinstaller/pyinstaller) - Converts Python programs into stand-alone executables (cross-platform). - [Nuitka](https://github.com/Nuitka/Nuitka) - Compiles Python programs into high-performance standalone executables (cross-platform). - - [shiv](https://github.com/linkedin/shiv) - A command line utility for building fully self-contained zipapps (PEP 441), but with all their dependencies included. + - [pex](https://github.com/pex-tool/pex) - A tool for building self-contained Python executable environments (PEP 441 zipapps). - [cx-Freeze](https://github.com/marcelotduarte/cx_Freeze) - Converts Python scripts into standalone executables and installers for Windows, macOS, and Linux. - Obfuscation - [pyarmor](https://github.com/dashingsoft/pyarmor) - A tool used to obfuscate python scripts, bind obfuscated scripts to fixed machine or expire obfuscated scripts. From 27c2ef5407dd65ac111fc117e99534962f5ed291 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:46:40 +0800 Subject: [PATCH 41/50] fix: point hydra-core to hydra-ecosystem/hydra hydra-core linked facebookresearch/hydra, which redirects to hydra-ecosystem/hydra after a repo transfer (same GitHub repo id), and an earlier commit had treated the new location as an unrelated project. Co-Authored-By: Claude --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 747143c4..d80e9a08 100644 --- a/README.md +++ b/README.md @@ -1108,7 +1108,7 @@ _Libraries for storing and parsing configuration options._ - [configparser](https://docs.python.org/3/library/configparser.html) - (Python standard library) INI file parser. - [python-dotenv](https://github.com/theskumar/python-dotenv) - Reads key-value pairs from a `.env` file and sets them as environment variables. - [pydantic-settings](https://github.com/pydantic/pydantic-settings) - Settings management using Pydantic models with validation, loading from environment variables and secrets files. -- [hydra-core](https://github.com/facebookresearch/hydra) - Hydra is a framework for elegantly configuring complex applications. +- [hydra-core](https://github.com/hydra-ecosystem/hydra) - Hydra is a framework for elegantly configuring complex applications. - [dynaconf](https://github.com/dynaconf/dynaconf) - Dynaconf is a configuration manager with plugins for Django and Flask. **Security** From e473d615e22fe0e987ce6790b8c8a165b2404cf8 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:47:03 +0800 Subject: [PATCH 42/50] audit: sweep Penetration Testing, drop social-engineer-toolkit Removed: social-engineer-toolkit (no PyPI download signal; not published on PyPI): a standalone social-engineering console rather than something Python developers use in their Python work, so it fails Serves Python Developers; its pyproject also requires Python >=3.11,<3.14. Its slot goes to impacket and pwntools in the next commits. Co-Authored-By: Claude --- README.md | 1 - 1 file changed, 1 deletion(-) diff --git a/README.md b/README.md index d80e9a08..f71144f5 100644 --- a/README.md +++ b/README.md @@ -1129,7 +1129,6 @@ _Frameworks and tools for penetration testing._ - [mitmproxy](https://github.com/mitmproxy/mitmproxy) - An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. - [sqlmap](https://github.com/sqlmapproject/sqlmap) - Automatic SQL injection and database takeover tool. - [sherlock-project](https://github.com/sherlock-project/sherlock) - Hunt down social media accounts by username across social networks. -- [social-engineer-toolkit](https://github.com/trustedsec/social-engineer-toolkit) - A toolkit for social engineering. ### Supply Chain Security From b0d8126e7333782bea312a46d6b1819711aa26d2 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:47:15 +0800 Subject: [PATCH 43/50] feat: add impacket to Penetration Testing Penetration Testing had no library for Windows and Active Directory protocol work (SMB, Kerberos, NTLM relay). Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index f71144f5..1d8bf353 100644 --- a/README.md +++ b/README.md @@ -1127,6 +1127,7 @@ _Libraries for cryptographic primitives and secure protocols._ _Frameworks and tools for penetration testing._ - [mitmproxy](https://github.com/mitmproxy/mitmproxy) - An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. +- [impacket](https://github.com/fortra/impacket) - A collection of Python classes for working with network protocols, widely used for Windows and Active Directory testing. - [sqlmap](https://github.com/sqlmapproject/sqlmap) - Automatic SQL injection and database takeover tool. - [sherlock-project](https://github.com/sherlock-project/sherlock) - Hunt down social media accounts by username across social networks. From 08b53fb6dcc5eb5e302101b9afc7baa58b73237f Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:47:24 +0800 Subject: [PATCH 44/50] feat: add pwntools to Penetration Testing Penetration Testing had no exploit-development library that Python developers import in their own code. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 1d8bf353..eada9213 100644 --- a/README.md +++ b/README.md @@ -1129,6 +1129,7 @@ _Frameworks and tools for penetration testing._ - [mitmproxy](https://github.com/mitmproxy/mitmproxy) - An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. - [impacket](https://github.com/fortra/impacket) - A collection of Python classes for working with network protocols, widely used for Windows and Active Directory testing. - [sqlmap](https://github.com/sqlmapproject/sqlmap) - Automatic SQL injection and database takeover tool. +- [pwntools](https://github.com/Gallopsled/pwntools) - A CTF framework and exploit development library. - [sherlock-project](https://github.com/sherlock-project/sherlock) - Hunt down social media accounts by username across social networks. ### Supply Chain Security From 9ce9828f5ac0eceeced1e1bf4c665640e59ba043 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:47:36 +0800 Subject: [PATCH 45/50] feat: add nh3 to Web Security Web Security had no HTML sanitizer since bleach was removed as deprecated; only justhtml in HTML Manipulation sanitizes, as part of parsing. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index eada9213..7c77cc42 100644 --- a/README.md +++ b/README.md @@ -1143,6 +1143,7 @@ _Tools for auditing dependencies against known vulnerabilities._ _Libraries for application-layer web security._ +- [nh3](https://github.com/messense/nh3) - Python binding to the ammonia HTML sanitizer, a fast replacement for bleach. - [secure](https://github.com/TypeError/secure) - HTTP security headers for Python web applications with ASGI and WSGI middleware. **Other** From a83abf25c615cdf249cbeda31eeb924e97c7f14d Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:47:49 +0800 Subject: [PATCH 46/50] style: reorder Hardware and Microsoft Windows by downloads Two sections broke the downloads-order rule: bleak sat above pynput, which has more downloads, and pythonnet sat above pywin32, which has about seven times more. Co-Authored-By: Claude --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 7c77cc42..695b10b0 100644 --- a/README.md +++ b/README.md @@ -1152,16 +1152,16 @@ _Libraries for application-layer web security._ _Libraries for programming with hardware._ -- [bleak](https://github.com/hbldh/bleak) - A cross platform Bluetooth Low Energy Client for Python using asyncio. - [pynput](https://github.com/moses-palmer/pynput) - A library to control and monitor input devices. +- [bleak](https://github.com/hbldh/bleak) - A cross platform Bluetooth Low Energy Client for Python using asyncio. - [jumpstarter](https://github.com/jumpstarter-dev/jumpstarter) - A hardware-in-the-loop testing framework with a Python client library for automated testing on real and virtual hardware. ### Microsoft Windows _Python programming on Microsoft Windows._ -- [pythonnet](https://github.com/pythonnet/pythonnet) - Python Integration with the .NET Common Language Runtime (CLR). - [pywin32](https://github.com/mhammond/pywin32) - Python Extensions for Windows. +- [pythonnet](https://github.com/pythonnet/pythonnet) - Python Integration with the .NET Common Language Runtime (CLR). - [pyenv-win](https://github.com/pyenv-win/pyenv-win) - A Python version manager for Windows ([rbenv-win](https://github.com/nak1114/rbenv-win) fork). - [winpython](https://github.com/winpython/winpython) - Portable Python distribution for Windows. From a48b05a8c117a9f227aedf96ddac0e0f9de36370 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:48:01 +0800 Subject: [PATCH 47/50] feat: add pyserial to Hardware Hardware had no serial-port library, though pyserial is the standard answer at about 12M downloads/month, roughly 8x the largest listed Hardware entry. Co-Authored-By: Claude --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 695b10b0..3e07804e 100644 --- a/README.md +++ b/README.md @@ -1152,6 +1152,7 @@ _Libraries for application-layer web security._ _Libraries for programming with hardware._ +- [pyserial](https://github.com/pyserial/pyserial) - Python serial port access library for Windows, macOS, Linux, and BSD. - [pynput](https://github.com/moses-palmer/pynput) - A library to control and monitor input devices. - [bleak](https://github.com/hbldh/bleak) - A cross platform Bluetooth Low Energy Client for Python using asyncio. - [jumpstarter](https://github.com/jumpstarter-dev/jumpstarter) - A hardware-in-the-loop testing framework with a Python client library for automated testing on real and virtual hardware. From bf3785400f4868f4c572e2cafc3a3051c857feff Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:48:29 +0800 Subject: [PATCH 48/50] style: use canonical PyPI names for four entries Four display names broke the naming convention (display name = PyPI package name): jupyter linked the notebook project while PyPI jupyter is a metapackage, and factory_boy, pygobject and kivy differ from their PyPI names factory-boy, PyGObject and Kivy. Co-Authored-By: Claude --- README.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 3e07804e..33ac5c54 100644 --- a/README.md +++ b/README.md @@ -612,7 +612,7 @@ _Python implementation of data structures, algorithms and design patterns. Also _Interactive Python interpreters (REPL)._ - [ipython](https://github.com/ipython/ipython) - A powerful interactive Python shell, and the kernel behind Jupyter notebooks. -- [jupyter](https://github.com/jupyter/notebook) - A web-based notebook environment for interactive computing. +- [notebook](https://github.com/jupyter/notebook) - A web-based notebook environment for interactive computing. - [awesome-jupyter](https://github.com/markusschanta/awesome-jupyter) - [marimo](https://github.com/marimo-team/marimo) - Transform data and train models, feels like a next-gen notebook, stored as Git-friendly Python. - [ptpython](https://github.com/prompt-toolkit/ptpython) - Advanced Python REPL built on top of the [python-prompt-toolkit](https://github.com/prompt-toolkit/python-prompt-toolkit). @@ -671,7 +671,7 @@ _Libraries for testing codebases and generating test data. Also see [awesome-pyt - [respx](https://github.com/lundberg/respx) - Mock HTTPX with awesome request patterns and response side effects. - [time-machine](https://github.com/adamchainz/time-machine) - Travel through time in your tests by mocking the current time at the C level. - Object Factories - - [factory_boy](https://github.com/FactoryBoy/factory_boy) - A test fixtures replacement for Python. + - [factory-boy](https://github.com/FactoryBoy/factory_boy) - A test fixtures replacement for Python. - [polyfactory](https://github.com/litestar-org/polyfactory) - A mock data generation library based on type hints (continuation of `pydantic-factories`). - Code Coverage - [coverage](https://github.com/coveragepy/coveragepy) - Code coverage measurement. @@ -852,9 +852,9 @@ _Useful CLI-based tools._ _Libraries for working with graphical user interface applications._ - Desktop - - [pygobject](https://github.com/GNOME/pygobject) - Python Bindings for GLib/GObject/GIO/GTK. + - [PyGObject](https://github.com/GNOME/pygobject) - Python Bindings for GLib/GObject/GIO/GTK. - [dearpygui](https://github.com/hoffstadt/DearPyGui) - A simple GPU-accelerated Python GUI framework. - - [kivy](https://github.com/kivy/kivy) - An open-source framework for cross-platform GUI apps on desktop, mobile, and embedded platforms. + - [Kivy](https://github.com/kivy/kivy) - An open-source framework for cross-platform GUI apps on desktop, mobile, and embedded platforms. - [wxPython](https://github.com/wxWidgets/Phoenix) - A cross-platform GUI toolkit that wraps the wxWidgets C++ library. - [toga](https://github.com/beeware/toga) - A Python native, OS native GUI toolkit. - Qt From 462dc31d98a2502f84ddf84942014d3272d1fa27 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:48:46 +0800 Subject: [PATCH 49/50] fix: add null pypi overrides for conda and pyodide The download sweep queried PyPI by display name, but PyPI conda is a stale 2017 upload and PyPI pyodide is a 0.0.2 placeholder, so the site showed unrelated packages' download counts for both entries. Co-Authored-By: Claude --- website/data/pypi_name_overrides.json | 2 ++ 1 file changed, 2 insertions(+) diff --git a/website/data/pypi_name_overrides.json b/website/data/pypi_name_overrides.json index 8c63c2c6..b4ba2946 100644 --- a/website/data/pypi_name_overrides.json +++ b/website/data/pypi_name_overrides.json @@ -3,6 +3,7 @@ "azure-sdk-for-python": { "package": null, "reason": "monorepo umbrella; ships as many azure-* packages, no single package represents it", "badge": "Multiple on PyPI" }, "cloud-init": { "package": null, "reason": "installed via distro images, not pip" }, "concurrent-futures": { "package": null, "reason": "stdlib module" }, + "conda": { "package": null, "reason": "installed via Miniforge or Anaconda installers; PyPI conda is a stale 2017 upload" }, "cpython": { "package": null, "reason": "not pip-installable; the cpython PyPI name was squatted" }, "devpi": { "package": "devpi-server", "reason": "devpi is a deprecated metapackage; the server package carries real usage" }, "difflib": { "package": null, "reason": "stdlib module" }, @@ -23,6 +24,7 @@ "pangu-py": { "package": "pangu", "reason": null }, "playwright-python": { "package": "playwright", "reason": null }, "pyenv": { "package": null, "reason": "installed via git/homebrew; PyPI pyenv is a defunct shim" }, + "pyodide": { "package": null, "reason": "runs in the browser from a CDN or npm; PyPI pyodide is a 0.0.2 placeholder from 2021" }, "pypy": { "package": null, "reason": "interpreter distributed via pypy.org, not pip" }, "python-patterns": { "package": null, "reason": "reference repo, not a package; PyPI name held by unrelated 2012 project" }, "pytorch": { "package": "torch", "reason": "PyPI pytorch is a squatter; real package is torch" }, From abff0608aba093cc0c7eae80257ce615a7d3c035 Mon Sep 17 00:00:00 2001 From: Vinta Chen Date: Fri, 2 Oct 2026 12:49:24 +0800 Subject: [PATCH 50/50] docs: record the 2026-10-02 audit overrides Standing maintainer decisions (the August schedule and httpie keeps, uv-audit's experimental status, jev-ultrafast's admission, the three 6-entry caps) lived only in old commit bodies or conversation, so the next audit would re-drop them as rule failures. Co-Authored-By: Claude --- docs/audit-logs.md | 21 ++++++++++++++++----- 1 file changed, 16 insertions(+), 5 deletions(-) diff --git a/docs/audit-logs.md b/docs/audit-logs.md index fb6b0a40..f99b64ce 100644 --- a/docs/audit-logs.md +++ b/docs/audit-logs.md @@ -29,11 +29,7 @@ Entries admitted despite the Stable quality requirement, by maintainer decision: - zensical -- admitted 2026-08-23 at version 0.0.57, PyPI classifier `Development Status :: 3 - Alpha`, with no 1.0 target announced. Admitted as a challenger displacing mkdocs because the Documentation section was carrying a dying upstream: the Material for MkDocs team's announcement of 2025-11-05 put Material into maintenance mode for twelve months and called MkDocs itself unmaintained since 2024-08 and a supply chain risk. Re-check when 1.0 lands. - openviking -- admitted 2026-08-25 (PR #3302) at version 0.4.16, PyPI classifier `Development Status :: 3 - Alpha`, with a README that said "OpenViking is still in its early stages". Admitted as a Data Layer challenger because the adoption is real: 459,446 downloads/month on pypistats (mirror-excluded) on 2026-08-24, and releases every few days. Re-check when 1.0 lands. - claude-agent-sdk -- kept 2026-10-01 in the AI and Agents audit at version 0.2.163, PyPI classifier `Development Status :: 3 - Alpha`. Kept as a Vendor Agent SDKs obvious choice because the adoption is real: 30,033,689 downloads/month on ClickPy on 2026-10-01, up from 1.2M in March 2026 on pypistats. Re-check when 1.0 lands. -- keras -- kept 2026-10-02 in the AI & ML audit as a Deep Learning Frameworks Second Tier challenger at version 3.15.1, PyPI classifier `Development Status :: 4 - Beta`. Kept because Keras 3 is a production multi-backend API; the classifier lags the project. -- stanza -- kept 2026-10-02 in the AI & ML audit as an NLP General challenger at version 1.15.0, PyPI classifier `Development Status :: 4 - Beta`. Kept because it is Stanford NLP's official library with releases through 2026-10-01; the classifier lags the project. -- kornia -- kept 2026-10-02 in the AI & ML audit as a Computer Vision General challenger at version 0.8.3, PyPI classifier `Development Status :: 4 - Beta`. Kept on 2,181,803 downloads/month on pypistats; the classifier lags the project. -- implicit -- kept 2026-10-02 in the AI & ML audit as a Recommender Systems obvious choice at version 0.7.3, PyPI classifier `Development Status :: 4 - Beta`. Kept on 234,833 downloads/month on pypistats and cp314 wheels; the classifier lags the project. -- statsforecast -- admitted 2026-10-02 in the AI & ML audit as a Time Series Forecasting obvious choice at version 2.1.1, PyPI classifier `Development Status :: 4 - Beta`. Admitted on 1,339,344 downloads/month on pypistats; the classifier lags the project. +- uv-audit -- kept 2026-08-16 as a Supply Chain Security entry, recorded 2026-10-02. uv itself prints "`uv audit` is experimental and may change without warning". Kept because it is part of uv, the obvious package manager. Re-check when uv drops the experimental notice. ### Challenger Exceptions @@ -41,14 +37,29 @@ Entries admitted as challengers without adoption-trajectory evidence, by maintai - seleniumbase -- admitted 2026-08-16 (PR #3284) as a Browser Automation challenger. It wraps selenium, the successor trajectory in the use case belongs to playwright, and its distinct value is its stealth/UC mode. Admitted because that stealth value counts toward Browser Automation. - semantica -- kept 2026-10-01 in the AI and Agents audit as a Data Layer challenger at 16,582 downloads/month on ClickPy, with no adoption-trajectory evidence found. Kept by maintainer decision. +- jev-ultrafast -- kept 2026-09-24 as a Web Scraping Frameworks challenger, recorded 2026-10-02. Admitted while the repo was under a month old and not on PyPI, so it has no download signal and no adoption-trajectory evidence; its README calls it an MVP and it needs a hosted TypeSafe API key. Kept by maintainer decision. + +### Cap Exceptions + +Use cases holding more than 5 entries, by maintainer decision: + +- Asynchronous Programming > Async I/O -- 6 entries since the 2026-08-16 split (19875cf), recorded 2026-10-02. +- Code Analysis > Linters and Formatters -- 6 entries since Security Linters merged in on 2026-08-16 (3290ce5), recorded 2026-10-02. +- Package Management > Package Managers -- 6 entries since the subcategory was minted on 2026-08-16 (1b51907), recorded 2026-10-02. ### Mature-stable Keeps These entries sit past the 12-month activity requirement without an override. Each one is kept by editorial judgment: mature, stable, and no successor exists. - annoy -- kept 2026-10-02 in the AI & ML audit, last push 2025-10-29. Unlike the others it has a successor, Spotify's own Voyager (2023), but kept by maintainer decision on 911,913 downloads/month on pypistats. +- blinker -- recorded 2026-10-02 ahead of its activity-line crossing on 2026-11-19 (last push 2025-11-19, last release 1.9.0 on 2024-11-08). Flask requires it. +- diskcache -- kept 2026-10-02, last push 2024-08-10, last release 5.6.3 (2023-08-31). Kept despite an unpatched pickle deserialization advisory, CVE-2025-69872 (GHSA-w8v5-vhqr-4h9v), on 25,526,045 downloads/month on ClickPy. +- django-rules -- recorded 2026-10-02 ahead of its activity-line crossing on 2026-10-11 (last push 2025-10-11, last release 3.5 on 2024-09-02). - ftfy +- httpie -- kept 2026-08-16, recorded 2026-10-02. Last commit 2024-12-17, last release 3.2.4 on 2024-11-01. - itsdangerous - jieba - jinja +- python-pptx -- kept 2026-10-02, last commit 2024-08-06, last release 1.0.2 on 2024-08-07. No successor for generating .pptx files. +- schedule -- kept 2026-08-16, recorded 2026-10-02. Last commit 2024-05-25. - sortedcontainers