pyyml
Use python in yaml
Decision gist · record as of 2026-08-14
No. The package is abandoned with no updates since April 2019, and its security model—executing Python code embedded in YAML—poses risks if configuration sources are untrusted. Modern alternatives or explicit post-processing of YAML are safer. Only consider it for legacy systems already using it.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires pyyaml as a runtime dependency; YAML files must use ${...} syntax for Python expressions and optional # libs:[...] header for imports.
- Low install friction with a single dependency (pyyaml), but the package has been abandoned since its initial release in April 2019 with no updates or maintenance.
License · maintenance · safety
MIT (permissive) — MIT license permits commercial and private use with minimal restrictions, though the abandoned status means no ongoing legal or security review.
last release 2019-04-09 (2684 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 432,712 downloads/mo, #6,706 on PyPI
Alternatives
Verify before relying
from pyyml import load
with open('conf.yml') as f:
config = load(f.read())
# YAML file with: sum: ${1 + 1}
# Results in: {'sum': 2}- Whether the package works reliably with current Python versions, given its age and lack of maintenance
- Security implications of executing arbitrary Python code embedded in YAML files during parsing
- Compatibility with modern pyyaml versions and whether breaking changes have occurred
What it is and what it does
pyyml extends YAML parsing to allow Python code execution within YAML files. When you load a YAML file through pyyml, any expression wrapped in ${...} is evaluated as Python code and replaced with its result. You can also import packages at the top of your YAML file using a special # libs:[...] comment syntax, making those modules available to your expressions.
This is useful for configuration files that need computed values—file paths, sums, environment-dependent settings—without leaving YAML syntax. However, the package has received no maintenance since its initial release in April 2019 and depends on pyyaml, which has evolved significantly. The security model of executing arbitrary Python in YAML requires careful vetting of configuration sources.
Use it for
- Generate computed configuration values (e.g., derived paths, sums) directly in YAML without post-processing
- Build environment-aware configs that reference os or other standard library modules within YAML
- Reduce boilerplate by embedding simple Python logic in configuration files instead of wrapper scripts
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The package is abandoned with no updates since April 2019, and its security model—executing Python code embedded in YAML—poses risks if configuration sources are untrusted. Modern alternatives or explicit post-processing of YAML are safer. Only consider it for legacy systems already using it.
Install
pyyml on PyPI
Before you install
Low install friction with a single dependency (pyyaml), but the package has been abandoned since its initial release in April 2019 with no updates or maintenance.
Requires pyyaml as a runtime dependency; YAML files must use ${...} syntax for Python expressions and optional # libs:[...] header for imports.
License in practice
MIT license permits commercial and private use with minimal restrictions, though the abandoned status means no ongoing legal or security review.
Quickstart
from pyyml import load
with open('conf.yml') as f:
config = load(f.read())
# YAML file with: sum: ${1 + 1}
# Results in: {'sum': 2}
Verify before relying
- Whether the package works reliably with current Python versions, given its age and lack of maintenance
- Security implications of executing arbitrary Python code embedded in YAML files during parsing
- Compatibility with modern pyyaml versions and whether breaking changes have occurred
Package facts
| License | MIT permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagepyyaml |
| Maintenance | Abandoned 2,684 days since the last release |
| First released | |
| Downloads | 432,712 / month, #6,706 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
Evidence: pyyml-0.0.2-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “yaml with code evaluation”
- pyymlEmbeds Python expressions directly in YAML files, evaluating them at…
- agent-framework-declarativeEnables building agents from YAML specifications using Microsoft's…
- lm-evalUnified framework for evaluating generative language models against…
Give your agent the search over MCP, or paste the wish link into any chat.
More Markup packages
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
A Python markdown parser that converts markdown to HTML following the CommonMark specification, with support for plugins and custom syntax rules.
Install it if you need reliable markdown-to-HTML conversion.
Beautiful Soup parses HTML and XML documents into a navigable tree, providing Pythonic methods to search, iterate, and modify the parsed content.
Install it if you need to parse or extract data from markup documents.
et_xmlfile writes large XML files with minimal memory overhead by serializing elements to disk as they are created, rather than holding the entire tree in memory.
Install it if incremental XML writing fits your use case; skip it if your XML documents are small or you already use lxml.
Parses and edits TOML files while preserving formatting, comments, and structure, then serializes them back with layout intact.
Install it if you're building tools that touch TOML files and user readability of the source matters.
Parses Python docstrings in ReST, Google, Numpydoc, and Epydoc formats, extracting structured information like descriptions, parameters, return types, and exceptions.
Install it if you need to programmatically read and extract structured data from Python docstrings.
See also yte · HiYaPyCo · anyconfig · pyyaml-include · empy · dynamic-yaml · HyperPyYAML · ruamel.yaml.jinja2 · envyaml · tfparse