dparse2
A parser for Python dependency files
Decision gist · record as of 2026-08-14
Yes, if you need to parse Python dependency files programmatically and can accept dormant maintenance. The package is stable, has no known vulnerabilities, and low install friction. However, the last release was in 2022—if you encounter bugs or need support for new dependency formats, you may need to fork or patch it yourself.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.6 or later; pipenv extra must be installed separately if Pipfile updates are needed.
- Low install friction with three lightweight runtime dependencies (packvers, pyyaml, toml).
- Maintenance is dormant—last release was in 2022 and the repository shows minimal recent activity, though it remains a maintained fork of an upstream project that stopped updating.
License · maintenance · safety
MIT (permissive) — MIT license is permissive and poses no restrictions on use, modification, or distribution in commercial or private projects.
last release 2022-12-23 (1330 days) · last repo commit 2024-08-21 · 2 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 130,426 downloads/mo, #11,640 on PyPI
Alternatives
Verify before relying
from dparse2 import parse, filetypes
content = "South==1.0.1\npycrypto>=2.6"
df = parse(content, file_type=filetypes.requirements_txt)
print(df.json())- Whether the package handles all edge cases in modern Python dependency formats (e.g., PEP 508 environment markers, direct URL references)
- Performance characteristics when parsing large or deeply nested dependency files
- Whether the pipenv extra dependency is still maintained and functional
What it is and what it does
dparse2 is a maintained fork of the original dparse library that parses Python dependency manifests and extracts structured information about each dependency. It reads requirements.txt, Pipfile, Pipfile.lock, conda.yml, tox.ini, and setup.cfg files, then returns parsed data as JSON-serializable objects containing package names, version specifications, hashes, and other metadata.
The package is designed for tools that need to analyze or process Python project dependencies programmatically. It depends on packvers, pyyaml, and toml for parsing different file formats. The fork was created because the original upstream project became unresponsive; this version supports Python 3.6 through 3.11 and has been marked Production/Stable, though active maintenance has stalled.
Use it for
- Analyze dependencies in a Python project to detect version conflicts or outdated packages
- Extract and validate hashes from requirements files for supply-chain security checks
- Convert between different dependency file formats by parsing one and regenerating another
- Build a dependency graph or audit trail from conda.yml or Pipfile.lock for compliance reporting
- Integrate dependency parsing into a CI/CD pipeline to validate manifest syntax before deployment
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to parse Python dependency files programmatically and can accept dormant maintenance.
The package is stable, has no known vulnerabilities, and low install friction. However, the last release was in 2022—if you encounter bugs or need support for new dependency formats, you may need to fork or patch it yourself.
Install
dparse2 on PyPI
Before you install
Low install friction with three lightweight runtime dependencies (packvers, pyyaml, toml). Maintenance is dormant—last release was in 2022 and the repository shows minimal recent activity, though it remains a maintained fork of an upstream project that stopped updating.
Requires Python 3.6 or later; pipenv extra must be installed separately if Pipfile updates are needed.
License in practice
MIT license is permissive and poses no restrictions on use, modification, or distribution in commercial or private projects.
Quickstart
from dparse2 import parse, filetypes
content = "South==1.0.1\npycrypto>=2.6"
df = parse(content, file_type=filetypes.requirements_txt)
print(df.json())
Verify before relying
- Whether the package handles all edge cases in modern Python dependency formats (e.g., PEP 508 environment markers, direct URL references)
- Performance characteristics when parsing large or deeply nested dependency files
- Whether the pipenv extra dependency is still maintained and functional
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.6 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagespackverspyyamltoml |
| Maintenance | Dormant 1,330 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 130,426 / month, #11,640 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: dparse2-0.7.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “dependency manifest parser”
- dparse2Parses Python dependency manifests (requirements.txt, Pipfile,…
- m3u8Parses and generates m3u8 playlist files (HLS manifests) according to…
- dbt-artifacts-parserParses dbt artifact JSON files (catalog, manifest, run-results,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also dparse · pip-requirements-parser · requirements-detector · requirementslib · plette · manifestoo-core · pipfile · pip-upgrader · codemod-tox · docker-image-py