$npx skillfedfor your agent

creosote

Identify unused dependencies and avoid a bloated virtual environment.

Worth itPyPI Quality AssuranceReleased Mar 2026860.7K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — creosote-5.2.0-py3-none-any.whl
v5.2.0 · released 2026-03-28 · Python >=3.10 · 6 runtime deps: dotty-dict, loguru, nbconvert, nbformat, pip-requirements-parser, tomli

Yes. Creosote solves a real problem—unused dependencies create security and maintenance burden—with low friction (pure Python, six lightweight deps) and active maintenance. It supports multiple dependency formats and integrates well into CI/pre-commit workflows. No known vulnerabilities and permissive MIT license. Install as a standalone tool to keep your project venv clean.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; you must have an activated virtual environment or site-packages folder path to scan, and a dependency specification file (pyproject.toml, requirements.txt, etc.) that creosote can parse.
  • Low install friction with a pure Python wheel and six runtime dependencies.
  • The project is actively maintained with a recent release and moderate popularity (top 5000 on PyPI), suggesting stable ongoing support.

License · maintenance · safety

permissive license (permissive) — Licensed under MIT (permissive), so you can use and modify creosote freely in both open-source and commercial projects without significant legal constraints.

last release 2026-03-28 (139 days) · last repo commit 2026-07-20 · 380 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 860,726 downloads/mo, #4,874 on PyPI

Verify before relying

# Install in a separate venv
uv tool install creosote

# Run from your project root
creosote --venv .venv --path src --deps-file pyproject.toml --section project.dependencies

# Or configure in pyproject.toml:
# [tool.creosote]
# venvs = [".venv"]
# paths = ["src"]
# deps-file = "pyproject.toml"
# sections = ["project.dependencies"]
  • Whether importlib-based dynamic imports can be detected (documentation notes this as a known limitation)
  • Performance characteristics when scanning large codebases or complex dependency graphs
  • Accuracy of deferred import detection when enabled via --include-deferred flag
Same gist for agents: .md · .json

What it is and what it does

Creosote is a command-line tool that identifies unused dependencies in your Python project by scanning source code for imports and comparing them against your declared dependencies. It works by parsing Python files for import statements, reading your dependency specification (pyproject.toml, requirements.txt, Poetry, Pipenv, or PDM formats), and determining which declared packages are never actually imported. The tool can also scan Django settings files for INSTALLED_APPS and MIDDLEWARE references.

You run it as a standalone tool (typically via `uv tool install creosote` to avoid polluting your project's venv) and configure it with command-line arguments or a `[tool.creosote]` section in pyproject.toml. It supports multiple venv paths, source directories, and dependency sections, and can optionally scan for deferred imports inside functions and conditional blocks. The output identifies which dependencies are unused so you can remove them, reducing virtual environment bloat and dependency maintenance burden.

Use it for

  • Run in CI to catch developers forgetting to remove unused dependencies during refactorings
  • Audit a legacy project to identify and remove accumulated unused packages before deployment
  • Integrate with pre-commit hooks to prevent unused dependencies from being committed
  • Scan Django projects to verify all INSTALLED_APPS and MIDDLEWARE entries are actually used
  • Reduce noise from dependency update bots by removing packages that won't actually break anything if dropped

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Creosote solves a real problem—unused dependencies create security and maintenance burden—with low friction (pure Python, six lightweight deps) and active maintenance. It supports multiple dependency formats and integrates well into CI/pre-commit workflows. No known vulnerabilities and permissive MIT license. Install as a standalone tool to keep your project venv clean.

Install

creosote on PyPI

Before you install

Low install friction with a pure Python wheel and six runtime dependencies. The project is actively maintained with a recent release and moderate popularity (top 5000 on PyPI), suggesting stable ongoing support.

Requires Python 3.10 or later; you must have an activated virtual environment or site-packages folder path to scan, and a dependency specification file (pyproject.toml, requirements.txt, etc.) that creosote can parse.

License in practice

Licensed under MIT (permissive), so you can use and modify creosote freely in both open-source and commercial projects without significant legal constraints.

Quickstart

# Install in a separate venv
uv tool install creosote

# Run from your project root
creosote --venv .venv --path src --deps-file pyproject.toml --section project.dependencies

# Or configure in pyproject.toml:
# [tool.creosote]
# venvs = [".venv"]
# paths = ["src"]
# deps-file = "pyproject.toml"
# sections = ["project.dependencies"]

Verify before relying

  • Whether importlib-based dynamic imports can be detected (documentation notes this as a known limitation)
  • Performance characteristics when scanning large codebases or complex dependency graphs
  • Accuracy of deferred import detection when enabled via --include-deferred flag

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
6 packages
dotty-dictlogurunbconvertnbformatpip-requirements-parsertomli
MaintenanceActively maintained 139 days since the last release
Last repo commit
First released
Downloads860,726 / month, #4,874 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy

Evidence: creosote-5.2.0-py3-none-any.whl

Tags

Capabilities
find unused dependenciesdetect unused importsclean up bloated venvdependency audit toolremove unused packagesdependency analyzervenv cleanup
Topics
dependency-auditci-integrationvenv-cleanup

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “find unused dependencies”

  • creosoteCreosote scans your Python project's source code and dependency…
  • pip-check-reqsAudits Python project imports against requirements.txt to find…
  • fawltydepsFawltydeps identifies undeclared dependencies (imports without…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also pip-check-reqs · pip-autoremove · fawltydeps · uv-sort · deptry · autoflake · pytest-unused-fixtures · deadcode · pycln · pipreqs