picobox
Dependency injection framework designed with Python in mind.
Decision gist · record as of 2026-08-14
Yes, if you want a pragmatic, lightweight DI solution without external dependencies. The zero-dependency design, thread-safety, and explicit injection model make it suitable for small to medium projects. However, the aging maintenance status means you should verify compatibility with your target Python version and assess whether the lack of recent updates aligns with your project's stability requirements.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.8 or later.
- Installation is frictionless—the package is pure Python with zero runtime dependencies and ships as a wheel.
- The codebase is lightweight (~500 LOC) and well-typed.
License · maintenance · safety
permissive license (permissive) — Licensed under MIT (permissive), so you can use, modify, and distribute picobox freely in commercial and open-source projects with minimal restrictions.
last release 2023-11-20 (998 days) · last repo commit 2025-04-06 · 51 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 310,283 downloads/mo, #7,747 on PyPI
Alternatives
Verify before relying
import picobox
box = picobox.Box()
box.put("key", "value")
with picobox.push(box):
@picobox.pass_("key")
def my_func(val):
return val
result = my_func()- Whether the aging maintenance status affects stability or compatibility with newer Python versions.
- Real-world performance characteristics under high-concurrency workloads despite thread-safety claims.
- Adoption patterns and ecosystem maturity relative to other DI frameworks in Python.
What it is and what it does
Picobox is a dependency injection framework that decouples code by managing object creation and lifecycle through explicit registration in named boxes. You register values or factories into a box, then use decorators to inject them into functions—the framework handles scope management (singleton, threadlocal, contextvars) and ensures thread-safe access. It avoids implicit injection and complex dependency graphs in favor of pragmatic, explicit demands.
The framework is designed for developers who want clean decoupling without heavyweight machinery. It supports both static values and factory functions, allows you to push boxes onto a stack for context-aware resolution, and stays lightweight at ~500 lines of code with no external dependencies. It works across Python 3.8–3.12 and both CPython and PyPy.
Use it for
- Inject configuration objects and database connections into request handlers in web applications.
- Manage thread-local or context-local service instances in multi-threaded or async codebases.
- Decouple business logic from external dependencies like HTTP clients or logging systems.
- Create testable code by swapping real implementations with mocks via different boxes.
- Organize factory functions for complex object creation without polluting module scope.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you want a pragmatic, lightweight DI solution without external dependencies.
The zero-dependency design, thread-safety, and explicit injection model make it suitable for small to medium projects. However, the aging maintenance status means you should verify compatibility with your target Python version and assess whether the lack of recent updates aligns with your project's stability requirements.
Install
picobox on PyPI
Before you install
Installation is frictionless—the package is pure Python with zero runtime dependencies and ships as a wheel. The codebase is lightweight (~500 LOC) and well-typed. Maintenance is aging: the last release was in November 2023, though the repository remains active.
Requires Python 3.8 or later.
License in practice
Licensed under MIT (permissive), so you can use, modify, and distribute picobox freely in commercial and open-source projects with minimal restrictions.
Quickstart
import picobox
box = picobox.Box()
box.put("key", "value")
with picobox.push(box):
@picobox.pass_("key")
def my_func(val):
return val
result = my_func()
Verify before relying
- Whether the aging maintenance status affects stability or compatibility with newer Python versions.
- Real-world performance characteristics under high-concurrency workloads despite thread-safety claims.
- Adoption patterns and ecosystem maturity relative to other DI frameworks in Python.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Aging 998 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 310,283 / month, #7,747 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Intended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Software Development :: Libraries |
Evidence: picobox-4.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “scope management singleton”
- picoboxPicobox is a lightweight dependency injection framework that manages…
- slackA dependency injection container that registers and provides…
- dependency-injectorDependency Injector is a dependency injection framework that…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also dependency-injector · wireup · dependencies · in-n-out · injector · slack · rodi · lagom · punq · gin-config