Commit Graph
1895 Commits
Author SHA1 Message Date
Jinyang 15b057c832 add openviking (#3302)
Deploy Website / deploy (push) Canceled after 0s
CI / test (push) Canceled after 0s
2026-08-25 08:08:40 +04:00
Jinyang dbb68d661d add semantica (#3301)
Deploy Website / deploy (push) Canceled after 0s
CI / test (push) Canceled after 0s
2026-08-24 10:42:58 +04:00
Vinta Chen 3daa2fa7a7 Merge pull request #3297 from karpetrosyan/add-hishel 2026-08-23 15:38:48 +08:00
Vinta ChenandClaude e6fe7d165c docs: point uv-audit entry link to its GitHub repo
Keep the docs link inline in the description instead of as the primary entry link, matching the format used by other entries.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-23 01:29:02 +08:00
Vinta ChenandClaude c07324b24f docs: rename uv audit entry to uv-audit and reword description
Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-23 01:15:33 +08:00
Vinta ChenandClaude 22e8208834 docs: remove httpx.URL entry from URL Manipulation
Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-23 01:15:29 +08:00
Vinta ChenandClaude 733021ae5b feat: add Bundled badge for entries shipped inside a larger project
django.db.models, geodjango, httpx.URL and uv audit were rendering
"Not on PyPI" alongside eighteen genuinely standalone projects that
simply are not packaged on PyPI, conflating two different reasons for
a missing download count.

These four entries now carry a "(part of X)" description prefix in
README.md, mirroring the existing "(Python standard library)"
convention. build.py reads that prefix into a bundled flag that both
templates render as a "Bundled" badge.

The prefix approach was chosen over a separate data file so README.md
stays the single source of content truth, and over inferring from the
entry name because geodjango is neither dotted nor spaced and would
have been missed. Redundant tail wording was trimmed from the
httpx.URL, geodjango and uv audit descriptions now that the prefix
names the parent.

The new entry format is documented in CONTRIBUTING.md and the
vocabulary in CONTEXT.md.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-23 01:09:20 +08:00
Vinta Chen b1f473319c clean up 2026-08-23 00:52:55 +08:00
Vinta ChenandClaude a2a0fee72a docs: replace mkdocs with zensical in Documentation section
Material for MkDocs went into maintenance mode on 2025-11-05 and its
own team called upstream mkdocs unmaintained since 2024-08 and a
supply chain risk; the mkdocs repo was last pushed 2025-10-20. Since
mkdocs-material hard-depends on mkdocs, mkdocs' download count is
almost entirely mkdocs-material pulling it in (18,360,677/month vs
mkdocs-material's 18,167,775/month, ~1% delta), so dropping the
redundant direct entry costs little. zensical is a clean replacement
with no mkdocs dependency, built by the same Material for MkDocs
team, at 1,585,786 downloads/month and 5,540 stars, pushed
2026-08-21. Added as a challenger, placed last below pdoc, keeping
the section at 5 of 5. Approved via verdict preview.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-23 00:48:25 +08:00
Vinta ChenandClaude 6bf9e8c5bf feat: add pint to Science > Physics and Engineering
Obvious choice for physical units and dimensional analysis in Python: 8,647,557 downloads/month (pepy.tech, 2026-08-23), more than twice astropy (3,713,879) and thirty-six times obspy (237,352), 2,781 stars, created 2012, pushed 2026-08-05. PyPI classifier still reads Beta at v0.25.3, treated as stale given fourteen years of history and download scale (judgment call). Listed under Physics and Engineering per maintainer choice over minting a Units and Quantities subcategory.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-23 00:47:49 +08:00
Vinta ChenandClaude 7d07309b23 feat: add complexipy to Code Analysis as a challenger
Audit of proposed additions from a YouTube video roundup. Admitted as
a challenger: 761,507 downloads/month (pepy.tech, 2026-08-23) already
outranks the incumbent prospector (497,880), the repo is active
(pushed 2026-08-21, version 7.0.1, Production/Stable) and it has
reached 794 stars since being created in January 2024. It fills a
real gap: ruff's PLR0912 measures cyclomatic complexity while
complexipy measures cognitive complexity, and the two are
complementary. Adoption-trajectory evidence is thin, so the
challenger tier is a judgment call. Placed last in the subcategory
since position marks tier and challengers follow obvious choices.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-23 00:47:22 +08:00
Vinta ChenandClaude 149cdd63bb feat: add python-statemachine as a challenger to transitions
Audit of proposed additions from a YouTube video roundup. transitions
has not been pushed since 2025-09-11 and crosses the 12-month activity
line on 2026-09-11, while python-statemachine is actively developed
(pushed 2026-08-17, version 3.2.1 released 2026-08-01) and covers
strictly more (SCXML-compliant statecharts, compound and parallel
states, history, sync and async). Downloads 1,422,332/month vs
transitions 3,137,416/month (pepy.tech, 2026-08-23).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-23 00:46:57 +08:00
Kar Petrosyan 62a7b5a275 docs: add hishel to Caching 2026-08-22 00:42:18 +04:00
Vinta ChenandClaude 49c2488244 docs: add httpx2 as challenger to HTTP Clients
Pydantic Services took over stewardship of the stalling httpx under the httpx2 name, Starlette already switched its TestClient, and it hit 144M downloads/month (pepy) within 3 months of first release at Production/Stable v2.12.0. Placed last in the challenger tier behind urllib3 per the downloads-descending ordering rule. Fork format and a rewritten description distinguish it from httpx, whose PyPI summary is identical.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-21 21:42:59 +08:00
Vinta Chen f3062087f0 Merge pull request #3284 from mdmintz/master
Add seleniumbase to Testing — Browser Automation as a challenger (2.86M downloads/month via pepy vs selenium 56.9M; admitted by maintainer decision). Entry placed per Entry Ordering, display name set to the canonical PyPI package name.
2026-08-16 21:03:04 +08:00
Vinta Chen e63de26416 update readme 2026-08-16 20:19:01 +08:00
Vinta ChenandClaude e9329d4d1e fix: correct hydra-core repo URL to facebookresearch/hydra
The entry linked hydra-ecosystem/hydra, an unrelated W3C Hydra API
toolkit, while the entry name and description describe
facebookresearch's Hydra configuration framework, mixing the wrong
repo's stars with the right package's identity. Found during the
downloads-column identity sweep.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 17:50:33 +08:00
Vinta ChenandClaude ecd9dea9e4 refactor: move pyenv-win from pyenv sub-item to full entry
Re-homed pyenv-win from a pyenv sub-item (Environment Management) to a full entry in Microsoft Windows, placed before winpython by downloads (25.8k/mo vs 172). Actively maintained, pushed 2026-08-14, 7,360 stars. Maintainer preference is to move sub-items to a fitting category rather than delete.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 16:47:02 +08:00
Vinta ChenandClaude 49b229bab4 refactor: promote flower from celery sub-item to full DevOps Monitoring entry
Flower isn't a task queue, so nesting it under celery misclassified it; Task Queues is also at its entry cap. Monitoring and Processes is its honest home, ranking fourth by downloads (12.35M/mo ClickPy, between supervisor 17.0M and sh 11.8M), and Celery's own docs name it the recommended monitor. Repo pushed 2026-08-16 with 7,232 stars. This fills Monitoring and Processes to its 5-entry cap.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 16:46:31 +08:00
Vinta ChenandClaude b0434abae6 refactor: promote mkdocs-material to full Documentation entry
Was a sub-item under mkdocs. By downloads it ranks second in the
section at 17.6M/mo (ClickPy), above mkdocs' 17.4M, and it powers
FastAPI, Pydantic, and Ruff/Polars docs (27,269 stars, pushed
2026-08-09). Documentation now sits at its 5-entry cap.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 16:45:57 +08:00
Vinta ChenandClaude 63a1eadd30 docs: remove typeshed sub-item from under mypy
Not a tool readers install: type checkers bundle it automatically as a
stub collection, it has no PyPI package, and no standalone use case.
The Type Checkers subcategory label already links to
awesome-python-typing for ecosystem depth.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 16:45:26 +08:00
Vinta ChenandClaude f13075b2af refactor: re-home aws-sdk-pandas from pandas sub-item to ETL General
Sub-item policy reserves sub-items for awesome-* links. aws-sdk-pandas
promoted out as awswrangler in Data Ingestion / ETL > General
(85.3M downloads/mo, 10x dlt, active).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 16:44:38 +08:00
Vinta Chen 08fdfa6a88 update readme 2026-08-16 16:25:00 +08:00
Vinta ChenandClaude f60d5b4a08 style: move fasthtml back to Web Frameworks > Synchronous
Maintainer reversal of c0a31ce, restoring the entry and its
awesome-fasthtml sub-item to their prior position. The
challenger-limit override that rode the move is withdrawn with it —
Asynchronous returns to 4 entries within the standard cap shape.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 15:25:15 +08:00
Vinta ChenandClaude 441f206d71 feat: add pathway to Data Ingestion / ETL
Re-admission on maintainer word, reversing the Data Analysis sweep's
drop (f3c920d — the xlsxwriter reversal precedent): the drop was
partly a mis-homing casualty, since its honest home, an ETL use case,
did not exist then. The repo self-describes as a Python ETL framework
for stream processing and LLM/RAG pipelines: 62.5K stars, pushed
daily; 16.5K downloads/month is weak for the star count and noted.
Enters as challenger behind dlt (7.8M/mo).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 15:24:38 +08:00
Vinta ChenandClaude e5f7b5bc2e style: update graphify link to the moved Graphify-Labs repo
The safishamsi/graphify URL is a stale redirect — the repo moved to
Graphify-Labs/graphify (verified via the GitHub API). Maintainer
declined the Agent Skills re-home; the entry stays in Data
Visualization > Specialized with its link fixed.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 15:21:21 +08:00
Vinta ChenandClaude 5249b756ce refactor: re-home fasthtml to Web Frameworks > Asynchronous
Maintainer-adjudicated close of the standing flag: fasthtml runs on
Starlette and Uvicorn (ASGI), so Synchronous was the wrong shelf. It
lands as a third challenger behind starlette and tornado's obvious
choices — the use case holds 5 with 3 challengers by explicit
maintainer override (Async I/O precedent; the awesome-fasthtml
sub-item rides along). 1.19M downloads/month as python-fasthtml.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 15:21:08 +08:00
Vinta ChenandClaude 15cd51c04c style: re-tier File Manipulation
No removals. mimetypes and pathlib (standard library) lead
alphabetically under the stdlib-first rule; watchfiles (389.3M/mo,
partly uvicorn-transitive — the riser) completes the obvious choices;
watchdog (113.3M/mo, the demoted incumbent, Second Tier) and
python-magic (32.3M/mo) challengers.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 15:10:10 +08:00
Vinta ChenandClaude ad698c2876 audit: sweep HTML Manipulation, drop html-to-markdown, pyquery, tinycss2
Tiers: beautifulsoup4 (renamed from beautifulsoup — the bare PyPI
name is the abandoned bs3 shim; 451.4M/mo, docs link per the PyQt
precedent), lxml (401.3M/mo), xmltodict (124.5M/mo) obvious choices;
markupsafe (820.5M/mo — the section's biggest raw count, but
jinja-transitive infrastructure, so challenger on judgment; watch:
quiet since 2025-09) and justhtml (67.8K/mo, 1.1K stars in two
years — trajectory judgment on a young pure-Python HTML5 parser)
challengers.

Removed:
- html-to-markdown — coordinated multi-entry self-promotion
  (automatic-rejection rule): PyPI provenance verified to xberg-io,
  the org's fourth planted entry overall. 1.5M downloads/month is
  real but the rule stands.
- pyquery — 2.2M downloads/month and an active repo (pushed
  2026-07); editorial drop at cap: the jQuery-style API is the
  least-reached-for of the keeps. Judgment call.
- tinycss2 — 110.5M downloads/month is transitive (weasyprint
  declares it a hard dependency, verified in PyPI metadata) against
  190 stars; a CSS parser mis-homed in an HTML/XML section with no
  better home. Judgment call.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 15:09:52 +08:00
Vinta ChenandClaude db9c262342 feat: add rapidfuzz, minting Text Processing > Fuzzy Matching
The industry's fuzzy string matching answer (web-verified: the
production recommendation over thefuzz — same API, MIT license, C++
speed — and preferred over textdistance for string metrics). 181.7M
downloads/month (pepy), 4.1K stars, pushed 2026-08. Sole obvious
choice; the subcategory label rides this commit so it is never empty,
completing the displacement of textdistance.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 15:09:32 +08:00
Vinta ChenandClaude 043cb6d377 feat: add charset-normalizer to Text Processing > Encoding and Unicode
The ecosystem's default encoding detector — requests switched to it
in 2021 and 2026 guidance names it the choice for new projects
(web-verified). 1.73B downloads/month (pepy; heavily
requests-transitive, but default-status is the point), pushed
2026-08. Co-obvious with chardet, which retains a verified accuracy
claim — the PyQt/PySide pair shape.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 15:09:18 +08:00
Vinta ChenandClaude da4383a06f audit: sweep Text Processing, dissolve General, drop textdistance, nameparser, user-agents, tree-sitter-language-pack
Restructure: the 10-entry General grab-bag dissolves — Encoding and
Unicode (chardet 224.1M/mo obvious choice, joined by
charset-normalizer next commit; ftfy 14.4M/mo kept as the fifth
mature-stable past-line keep, repo and release both 2024-10),
Internationalization (babel 135.2M/mo sole), Transliteration and
Slugs (python-slugify 87.7M/mo, unidecode 31.8M/mo), and a residual
General (difflib stdlib-first, pyfiglet 6.2M/mo judgment keep).
pypinyin (1.9M/mo) and pangu.py (14.9K/mo as PyPI pangu — display
name kept by explicit maintainer word, the second deliberate naming
exception after pytorch; kept on sole-tool judgment for CJK spacing)
re-home to Natural Language Processing > Chinese as challengers
beside jieba. Parser re-tiers: pygments (1.25B/mo), pyparsing
(422.3M/mo), sqlparse (146.8M/mo) obvious choices; phonenumbers
(renamed from python-phonenumbers, 39.4M/mo) and parsy (4M/mo)
challengers. Unique identifiers reorders to shortuuid then sqids.

Removed:
- textdistance — last release 2024-07 (25 months) and repo quiet
  since 2025-04, past the 12-month line; displaced by rapidfuzz
  (181.7M/mo vs 2.5M), entering in its own commit.
- python-nameparser — 3.3M downloads/month (as nameparser) and an
  active repo; editorial drop at cap: the domain-parser class is
  trimmed to the giant, phonenumbers. Judgment call.
- python-user-agents — repo quiet since 2023-02, three and a half
  years past the 12-month line.
- tree-sitter-language-pack — coordinated multi-entry self-promotion
  (automatic-rejection rule): PyPI provenance verified to xberg-io,
  the org that previously planted xberg and liter-llm. 6.6M/mo is
  real but the rule stands; its sibling drops from HTML Manipulation.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 15:09:02 +08:00
Vinta ChenandClaude 67c9f7ae93 style: split Computer Vision into General and OCR
No removals. General tiers: opencv-python (renamed from opencv to the
canonical pip package this entry already linked; 55.9M/mo) and
ultralytics (8.4M/mo, 60.7K stars) obvious choices; kornia (3.1M/mo)
and fiftyone (253.7K/mo — dataset tooling rather than a vision
algorithm library, kept as the unprompted answer for that adjacent
job) challengers. OCR minted as a distinct job: pytesseract (24M/mo)
and easyocr (3.6M/mo, quiet since 2025-12 — watch) obvious choices.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:48:57 +08:00
Vinta ChenandClaude c83b98c37e audit: sweep Natural Language Processing, drop funnlp
General tiers: nltk (71.4M/mo), spacy (25.4M/mo) obvious choices;
gensim (6M/mo, quiet since 2025-11 — watch) and stanza (1.1M/mo)
challengers. Chinese: jieba kept as mature-stable past the 12-month
activity line (repo quiet since 2024-08, last release 0.42.1 in
2020-01) on the sortedcontainers precedent — the fourth such keep:
3.3M downloads/month, 35.1K stars, still the Chinese segmentation
answer with no successor.

Removed:
- funnlp — three independent grounds: a link-collection rather than a
  library; repo quiet since 2024-05, past the 12-month line; 55
  downloads/month. Its 82.5K stars measure the bookmark, not a tool.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:48:38 +08:00
Vinta ChenandClaude 7d1c5c8d00 audit: sweep Machine Learning, three-way split, drop h2o, mindsdb, scikit-lego, TabGAN, spark.ml
Restructure: the 12-entry flat section splits into General
(scikit-learn 234.7M/mo obvious choice; pgmpy 843.7K/mo and
feature-engine — renamed from feature_engine to its canonical PyPI
name, 297.1K/mo — challengers), Gradient Boosting (xgboost 52M/mo,
lightgbm 26.5M/mo, catboost 6.3M/mo, all obvious choices; lightgbm's
lightgbm-org link verified current — microsoft/LightGBM redirects
there), and Time Series Forecasting (timesfm sole — a foundation
model judged by ecosystem adoption, 285K/mo and 27.6K stars; prophet
and darts are named absences, deliberately not added this sitting).

Removed:
- h2o — 215.1K downloads/month, 7.5K stars, and the repo is active;
  the drop is purely editorial: no longer anyone's unprompted answer
  against scikit-learn and the boosting trio. Judgment call.
- mindsdb — the linked repo redirects to mindsdb/mindshub, a "models
  workspace"; the AI-layer-for-databases product this entry described
  no longer exists (verified). 23.9K downloads/month.
- scikit-lego — 72.5K downloads/month, 1.4K stars; a grab-bag of
  sklearn extras that never became an unprompted answer. Judgment.
- TabGAN — 574 stars, 2.3K downloads/month. Nowhere near the bar.
- spark.ml — duplicate in all but name: pyspark is already listed in
  the audited DevOps group, same repo, same pip install. Structural.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:48:21 +08:00
Vinta ChenandClaude b95ce7e995 feat: add gymnasium to Deep Learning > Reinforcement Learning
The RL environments standard: community successor to OpenAI Gym
(unmaintained since 2022; few maintained RL libraries still support
old Gym — web-verified). 6.5M downloads/month (pepy), 12.3K stars,
pushed 2026-08. Obvious choice beside stable-baselines3, ordering
first by downloads.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:47:56 +08:00
Vinta ChenandClaude 34c550b864 style: split Deep Learning into Frameworks and Reinforcement Learning
No removals. Frameworks tiers: pytorch (96.6M/mo as PyPI torch — the
display name stays pytorch by explicit maintainer word, a deliberate
exception to the naming convention; the bare pytorch PyPI package is
a squatting placeholder), tensorflow (19.2M/mo — production incumbent,
flagged as a Second Tier demotion candidate for the next audit), keras
(18.6M/mo, backend-agnostic since Keras 3) obvious choices; jax
(21.8M/mo, TPU/performance trajectory) and pytorch-lightning
(11M/mo) challengers. Landscape verified: PyTorch is the 2026 default
with 85% research share.

stable-baselines3 moves into the minted Reinforcement Learning
subcategory — RL is a distinct job; gymnasium joins it next commit.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:47:44 +08:00
Vinta ChenandClaude 660d746237 style: move the ERP section to the Web Development group
Maintainer challenge upheld: Odoo is a ready-made web application
platform you extend, the sibling concept of CMS and Admin Panels —
so the section belongs beside them, not in the Other grab-bag (its
first placement was inertia from tryton's Miscellaneous home). TOC
and body both move; the group's section tail stays alphabetical
(Admin Panels, CMS, ERP, Static Site Generators).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:30:54 +08:00
Vinta ChenandClaude a2659635af feat: add odoo, minting the ERP section
The Python ERP by adoption: about 7M users across editions, 50+ app
modules, 53.7K stars, pushed daily (web-verified). Not pip-distributed
— the PyPI odoo package is a dateless placeholder — so no download
signal; judged by ecosystem and displayed by repository name (renpy
precedent). Sole obvious choice.

Second structure override of decision 18 by maintainer word (Supply
Chain Security precedent): ERP lands as a new section in the Other
group rather than a slot in the Miscellaneous grab-bag, replacing the
dropped tryton. TOC line, heading, and description ride this commit.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:27:23 +08:00
Vinta ChenandClaude f8e594a9b4 audit: sweep Miscellaneous, drop tryton, re-home itsdangerous to Cryptography
Restructure: itsdangerous moves to Security > Cryptography as a
challenger — HMAC-based data signing fits "cryptographic primitives
and secure protocols" better than the grab-bag. Kept past the
12-month activity line (repo quiet since 2025-06, last release
2024-04) as mature-stable on the sortedcontainers precedent: 222.8M
downloads/month, the signing answer, no successor. Miscellaneous
keeps blinker (192.2M/mo) and boltons (26.5M/mo) as obvious choices.

Removed:
- tryton — 10.9K downloads/month, and that PyPI package is the
  desktop client (the framework server is trytond); the linked GitHub
  repo is a self-described 216-star mirror; and the ERP obvious
  choice by adoption is Odoo (~7M users vs hundreds-to-thousands of
  Tryton deployments, web-verified), which enters in the next commit.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:27:02 +08:00
Vinta ChenandClaude 0194cbbe13 audit: sweep Hardware, drop synology-api
Tiers: bleak (2.5M/mo) and pynput (2.2M/mo) obvious choices;
jumpstarter (1.5K/mo, 211 stars, created 2026-01) kept as a
challenger by explicit maintainer flip against the seeded drop.

Removed:
- synology-api — 579 stars, 14.5K downloads/month; a single-vendor
  NAS API wrapper, not an obvious choice for any hardware job a
  general reader has. Judgment call.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:26:42 +08:00
Vinta ChenandClaude 16e17d62ba style: drop the preview label from uv audit's description
Maintainer word: no preview marker in the entry text. The stability
override itself stands unchanged.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:15:42 +08:00
Vinta ChenandClaude 913b380cc8 feat: add uv audit to Supply Chain Security
Maintainer-proposed during the Security sitting: uv's built-in
vulnerability and malware scanning (announced 2026-06, OSV-backed,
4-10x faster than pip-audit on typical projects). Enters as a
no-signal challenger behind pip-audit — not a package, so this is a
subcommand pointer entry linking the CLI docs (httpx.URL precedent).

Astral marks the feature preview/unstable; kept by explicit maintainer
override of the production-ready quality bar — the first stability
override. The description carries the preview label.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:15:21 +08:00
Vinta ChenandClaude fe7006edcc feat: add pip-audit, minting the Supply Chain Security section
The PyPA-official dependency vulnerability scanner: 30.9M
downloads/month (pepy; largely CI traffic, which is the use case),
1.3K stars, pushed 2026-08. Verified 2026 guidance names it the free
baseline over the older commercial safety. Sole obvious choice.

This mints the reform's first new section — an explicit maintainer
override of decision 18 (all minted use cases are subcategories),
accepted in the audit preview. TOC line, heading, and description
ride this commit per the Build Backends pattern; placed alphabetically
in the Security group.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:12:46 +08:00
Vinta ChenandClaude 438881adba style: audit Cryptography and Penetration Testing — renames and re-tiers
No removals in either section.

Cryptography: adds the missing italic section description; reorders to
downloads — cryptography (1.48B/mo), pynacl (241.7M/mo), paramiko
(155.4M/mo; SSH kept here as secure-protocols-adjacent rather than
minting a sole-entry use case) — all obvious choices.

Penetration Testing: tiers mitmproxy (10.8M/mo) and sqlmap (official
PyPI package verified, 65.3K/mo under-measures git-based usage; 38.2K
stars) obvious choices; sherlock-project (renamed from sherlock — the
bare PyPI name is an unrelated distributed-lock library; 115.9K/mo,
89.6K stars) and social-engineer-toolkit (renamed from setoolkit —
no PyPI package, so the naming convention falls back to the repository
name; no download signal, judged by ecosystem standing) challengers.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:12:29 +08:00
Vinta ChenandClaude 283f1425b3 style: fix display-name casing to canonical PyPI names
Maintainer-approved batch: gtts → gTTS, twisted → Twisted, cython →
Cython, per the naming convention (display name = canonical PyPI
package name, verified via the PyPI JSON API). All three were caught
post-commit in earlier sittings and parked awaiting explicit word.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:03:50 +08:00
Vinta ChenandClaude cf38a34ed4 refactor: re-home pre-commit to Code Analysis > Git Hooks
Maintainer-adjudicated close of the standing flag from the Developer
Tools sitting: pre-commit is developer-workflow tooling (a git-hook
framework orchestrating linters), not ops — it leaves the DevOps
Tools > Other grab-bag for a minted sole-entry Git Hooks subcategory
in Code Analysis. Placement avoids stretching the Linters and
Formatters cap override (already 6 by maintainer word). No additions
or removals — a pure re-home.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 14:03:35 +08:00
Vinta ChenandClaude ee0caca892 feat: add pydantic-settings to Configuration Files
Displacement of the dropped python-decouple: same job — settings from
environment variables and files — done with validation and types on
the pydantic ecosystem's momentum. 495M downloads/month (pepy), pushed
2026-08. Obvious choice, ordering after python-dotenv.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 13:54:05 +08:00
Vinta ChenandClaude 5a8c062f6d audit: sweep Configuration Files, drop python-decouple
Tiers: configparser (stdlib, leads the use case under the stdlib-first
ordering rule), python-dotenv (782.2M/mo) obvious choices —
pydantic-settings joins them in its own addition commit; hydra-core
(23.8M/mo — renamed from hydra to its canonical PyPI name; the cache's
bare hydra row is an ancient unrelated package; link updated to
hydra-ecosystem/hydra, where the facebookresearch repo now redirects,
target verified by description) and dynaconf (6.8M/mo) challengers.

Removed:
- python-decouple — repo dormant since 2024-11, last release 3.8 in
  2023-03, three and a half years past any release and past the
  12-month activity line. 8.4M downloads/month, 3.0K stars.
  Displaced by pydantic-settings (495M/mo) entering next.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 13:53:51 +08:00
Vinta ChenandClaude 9f9bd8db1f style: split Distribution into Executables and Obfuscation
Maintainer-directed restructure: instead of dropping pyarmor as
mis-homed, an Obfuscation subcategory is minted for it (sole obvious
choice — 501.5K/mo, 5.2K stars, pushed 2026-08); code obfuscation is a
distinct job from building executables. Executables tiers: pyinstaller
(13.1M/mo), Nuitka (512K/mo) obvious choices; shiv (487.3K/mo),
cx-Freeze (221K/mo) challengers. No removals.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 13:53:35 +08:00