pyodide-lock
Tooling to manage the `pyodide-lock.json` file
Decision gist · record as of 2026-08-14
Yes, if you are building or maintaining Pyodide, JupyterLite, or PyScript applications and need to manage lock files programmatically. The low install friction and active maintenance are positives. However, be aware that the pre-1.0 API is explicitly unstable and may break before the 0.1 release; pin your version or monitor releases closely if you adopt it early.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.12 or later.
- Low friction: pure Python wheel with only two lightweight dependencies (attrs and cattrs).
- Actively maintained with a recent release; however, the package is pre-1.0 and explicitly warns that its API may change substantially before the 0.1 release.
License · maintenance · safety
permissive license (permissive) — BSD-3-Clause license (permissive); safe for commercial and proprietary use with standard attribution requirements.
last release 2026-07-24 (21 days) · last repo commit 2026-07-24 · 8 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 76,675 downloads/mo, #14,602 on PyPI
Alternatives
Verify before relying
pip install pyodide-lock
from pyodide_lock import PyodideLockSpec
lock_spec = PyodideLockSpec.from_json("pyodide-lock.json")
# Make changes to lock_spec
lock_spec.to_json("pyodide-lock.json")- Whether the API stability warning (may change before 0.1 release) reflects ongoing active development or is outdated given the current 0.2.0 version.
- Whether PyodideLockSpec is the primary public API or if there are other entry points documented.
What it is and what it does
pyodide-lock is a tooling library for managing pyodide-lock.json files, which specify the versions of Python packages that are auto-loaded in Pyodide-based applications (including JupyterLite and PyScript). Instead of requiring explicit micropip installation at runtime, packages listed in the lock file are loaded automatically when the application starts. The library provides a Python API to read, modify, and write these lock files programmatically.
The package depends on attrs and cattrs for data structure handling and serialization. It is actively maintained and has low installation friction as a pure-Python wheel. However, it is pre-1.0 and explicitly warns that its API may change substantially before the 0.1 release, so early adopters should be prepared for potential breaking changes.
Use it for
- Programmatically update package versions in a pyodide-lock.json file as part of a CI/CD pipeline.
- Generate or regenerate lock files for JupyterLite or PyScript deployments from a Python script.
- Parse and inspect the current package manifest in an existing pyodide-lock.json to audit dependencies.
- Automate dependency management for Pyodide applications without manual JSON editing.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building or maintaining Pyodide, JupyterLite, or PyScript applications and need to manage lock files programmatically.
The low install friction and active maintenance are positives. However, be aware that the pre-1.0 API is explicitly unstable and may break before the 0.1 release; pin your version or monitor releases closely if you adopt it early.
Install
pyodide-lock on PyPI
Before you install
Low friction: pure Python wheel with only two lightweight dependencies (attrs and cattrs). Actively maintained with a recent release; however, the package is pre-1.0 and explicitly warns that its API may change substantially before the 0.1 release.
Requires Python 3.12 or later.
License in practice
BSD-3-Clause license (permissive); safe for commercial and proprietary use with standard attribution requirements.
Quickstart
pip install pyodide-lock
from pyodide_lock import PyodideLockSpec
lock_spec = PyodideLockSpec.from_json("pyodide-lock.json")
# Make changes to lock_spec
lock_spec.to_json("pyodide-lock.json")
Verify before relying
- Whether the API stability warning (may change before 0.1 release) reflects ongoing active development or is outdated given the current 0.2.0 version.
- Whether PyodideLockSpec is the primary public API or if there are other entry points documented.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.12 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesattrscattrs |
| Maintenance | Actively maintained 21 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 76,675 / month, #14,602 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3 |
Evidence: pyodide_lock-0.2.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “pyodide lock file management”
- pyodide-lockParses, modifies, and writes pyodide-lock.json files that specify…
- jupyterlite-pyodide-kernelProvides a Python kernel for JupyterLite that runs Python code in the…
- poetryPoetry is a dependency management and packaging tool that replaces…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also filelock · jupyterlite-pyodide-kernel · lockfile · zc.lockfile · pyodide-py · redlock-py · python-dynamodb-lock · fasteners · pyodide-cli · PyMySQLLock