poetry
Python dependency management and packaging made easy.
Decision gist · record as of 2026-08-14
Yes. Poetry is a mature, actively maintained tool with no known vulnerabilities, permissive licensing, and low install friction. It is widely adopted (top 1000 on PyPI with millions of monthly downloads) and solves a real problem—consolidating fragmented Python packaging workflows into a single, reproducible system. Install it if you want deterministic dependency management and modern packaging practices.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >=3.10,<4.0; Poetry manages its own virtual environments and may require system-level Python to be available.
- Low install friction with a pure-Python wheel distribution.
- Active maintenance with a recent release (97 days ago) and ongoing commits.
License · maintenance · safety
MIT (permissive) — MIT license permits commercial and private use with minimal restrictions, making it safe to adopt in most projects.
last release 2026-05-09 (97 days) · last repo commit 2026-08-10 · 34,290 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 85,290,141 downloads/mo, #397 on PyPI
Alternatives
Verify before relying
pip install poetry
poetry new my-project
cd my-project
poetry add requests
poetry install- Whether the 22 runtime dependencies introduce meaningful security surface or maintenance burden beyond the tool's own updates.
- Performance characteristics when managing very large dependency graphs or monorepo structures.
What it is and what it does
Poetry is a complete dependency management and packaging system for Python projects. It consolidates the roles of setup.py, requirements.txt, setup.cfg, MANIFEST.in, and Pipfile into a single pyproject.toml file, providing declarative dependency specification, deterministic lock files, and built-in virtual environment handling. It supports version constraints, optional dependencies, dependency groups (dev, docs, etc.), and git-based dependencies.
Developers use Poetry to declare project metadata and dependencies once, then Poetry handles installation consistency across environments, lock file generation for reproducible builds, and packaging for distribution. It integrates with the standard PEP 517 build system and works with modern Python versions (3.10 through 3.14). The tool is actively maintained and widely adopted in the Python ecosystem.
Use it for
- Manage dependencies and ensure reproducible builds across development, testing, and production environments using a single lock file.
- Organize dependencies into groups (dev, docs, lint) and install only what is needed for each context.
- Package and publish Python projects to PyPI with automatic version management and metadata handling.
- Migrate from legacy setup.py and requirements.txt workflows to a modern, standards-based pyproject.toml approach.
- Declare and resolve complex dependency constraints, including version ranges, extras, and environment-specific packages.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Poetry is a mature, actively maintained tool with no known vulnerabilities, permissive licensing, and low install friction. It is widely adopted (top 1000 on PyPI with millions of monthly downloads) and solves a real problem—consolidating fragmented Python packaging workflows into a single, reproducible system. Install it if you want deterministic dependency management and modern packaging practices.
Install
poetry on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Active maintenance with a recent release (97 days ago) and ongoing commits. Large dependency tree (22 runtime dependencies) is typical for a full-featured packaging tool and reflects its broad scope rather than a maintenance concern.
Requires Python >=3.10,<4.0; Poetry manages its own virtual environments and may require system-level Python to be available.
License in practice
MIT license permits commercial and private use with minimal restrictions, making it safe to adopt in most projects.
Quickstart
pip install poetry
poetry new my-project
cd my-project
poetry add requests
poetry install
Verify before relying
- Whether the 22 runtime dependencies introduce meaningful security surface or maintenance burden beyond the tool's own updates.
- Performance characteristics when managing very large dependency graphs or monorepo structures.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release <4.0,>=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 22 packagesbuildcachecontrolcleodulwichfastjsonschemafindpythoninstallerkeyringpackagingpbs-installerpkginfoplatformdirspoetry-corepyproject-hooksrequestsrequests-toolbeltshellinghamtomlitomlkittrove-classifiersvirtualenvxattr |
| Maintenance | Actively maintained 97 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 85,290,141 / month, #397 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Software Development :: Build ToolsTopic :: Software Development :: Libraries :: Python Modules |
Evidence: poetry-2.4.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “python dependency management”
- poetryPoetry is a dependency management and packaging tool that replaces…
- pipfileProvides a design specification and parser for Pipfile and…
- pdmPDM is a modern Python package and dependency manager that handles…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also nox-poetry · poetry-core · poetry-plugin-export · poetry-plugin-shell · vale · charmcraftlocal · poetry-dynamic-versioning · pip-upgrader · migrate-to-uv · poethepoet