dulwich
Python Git Library
Decision gist · record as of 2026-08-14
Yes, if you need Git repository access in pure Python without external dependencies. The package is actively maintained, has no known vulnerabilities, and low install friction. The unclear dual license requires verification before use in proprietary or GPL-sensitive contexts. Performance will be slower than native Git for large operations, but the trade-off is acceptable for most automation and analysis tasks.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later (CPython or PyPy); optional Rust bindings require a Rust toolchain to build from source.
- Low friction: pure Python wheel with only urllib3 and typing_extensions as runtime dependencies.
- Actively maintained with a release 26 days ago and last commit on 2026-08-13.
License · maintenance · safety
Apache-2.0 OR GPL-2.0-or-later (unclear) — License treatment is unclear: the package is dual-licensed under Apache-2.0 OR GPL-2.0-or-later. Users should verify which license terms apply to their use case before deploying.
last release 2026-07-19 (26 days) · last repo commit 2026-08-13 · 2,270 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 99,380,025 downloads/mo, #348 on PyPI
Alternatives
Verify before relying
pip install dulwich
from dulwich.repo import Repo
r = Repo('.')
head_commit = r[r.head()]
print(head_commit.message)- Whether the dual license (Apache-2.0 OR GPL-2.0-or-later) requires explicit license selection or if both can coexist in derivative works.
- Performance impact of pure Python implementation compared to native Git or pygit2 in typical workloads.
What it is and what it does
Dulwich is a pure Python implementation of Git that lets you read and write Git repositories without installing Git or native extensions. It provides both low-level APIs for direct repository access and higher-level porcelain functions for common Git operations. The main trade-off is speed for portability: since it's pure Python, it runs anywhere Python runs, making it useful in containerized or restricted environments where Git isn't available.
The package includes optional Rust bindings to accelerate low-level operations, but these are optional and not required for basic functionality. It aims for full wire-format and repository compatibility with C Git, meaning Dulwich and Git can work interchangeably on the same repository. Runtime dependencies are minimal (urllib3 and typing_extensions), and it supports Python 3.10 and later on both CPython and PyPy.
Use it for
- Access Git repositories programmatically in environments where Git is not installed or cannot be used.
- Build Git-based tools and automation in pure Python without spawning external processes.
- Implement custom Git workflows or integrations that need direct repository manipulation.
- Deploy Git operations in containerized or restricted environments where native dependencies are problematic.
- Parse and analyze Git history, commits, and metadata without relying on system Git.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need Git repository access in pure Python without external dependencies.
The package is actively maintained, has no known vulnerabilities, and low install friction. The unclear dual license requires verification before use in proprietary or GPL-sensitive contexts. Performance will be slower than native Git for large operations, but the trade-off is acceptable for most automation and analysis tasks.
Install
dulwich on PyPI
Before you install
Low friction: pure Python wheel with only urllib3 and typing_extensions as runtime dependencies. Actively maintained with a release 26 days ago and last commit on 2026-08-13. Optional Rust bindings are available but not required.
Requires Python 3.10 or later (CPython or PyPy); optional Rust bindings require a Rust toolchain to build from source.
License in practice
License treatment is unclear: the package is dual-licensed under Apache-2.0 OR GPL-2.0-or-later. Users should verify which license terms apply to their use case before deploying.
Quickstart
pip install dulwich
from dulwich.repo import Repo
r = Repo('.')
head_commit = r[r.head()]
print(head_commit.message)
Verify before relying
- Whether the dual license (Apache-2.0 OR GPL-2.0-or-later) requires explicit license selection or if both can coexist in derivative works.
- Performance impact of pure Python implementation compared to native Git or pygit2 in typical workloads.
Package facts
| License | Apache-2.0 OR GPL-2.0-or-later unclear |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesurllib3typing_extensions |
| Maintenance | Actively maintained 26 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 99,380,025 / month, #348 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableOperating System :: Microsoft :: WindowsOperating System :: POSIXProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Software Development :: Version Control |
Evidence: dulwich-1.2.12-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “pure python git library”
- dulwichDulwich provides pure Python access to Git repositories—both local…
- pygit2pygit2 provides Python bindings to libgit2, enabling direct…
- pathspecMatches file paths against gitignore-style patterns, supporting both…
Give your agent the search over MCP, or paste the wish link into any chat.
More Version Control packages
Automatically extracts and manages Python package versions from git or Mercurial metadata instead of hardcoding them, and includes SCM-tracked files in source distributions.
setuptools-rust is a setuptools plugin that compiles and packages Python extensions written in Rust, using PyO3 or rust-cpython bindings.
pygit2 provides Python bindings to libgit2, enabling direct programmatic access to Git repository operations at the plumbing level without shelling out to the git command-line tool.
A Poetry plugin that automatically derives and injects version numbers from version control tags into your project during builds, using Dunamai to support multiple VCS systems.
Install it if you use Poetry 1.2.0+ and want to eliminate manual version management in your build workflow.
Parses and applies patch files in multiple diff formats (unified, context, normal, ed, rcs) and from several source control systems (Git, SVN, CVS).
Automatically determines your Python package's version from Git or Mercurial tags and writes it to your build system, with customizable version formatting and optional runtime file generation.
See also scmrepo · gitdb2 · gitdb · GitPython · pecan · vcstool · pip · jeepney · cffi