pypa/pipenv
66.3
Adequate · 18 September 2026
308.4k
lines of production code
Python
primary language
1
measurement over time
What this system is
Pipenv is a Python environment and dependency management tool that handles virtual environment creation, package installation, and lock file generation. It features a pluggable resolver architecture with a new pure-Python PEP 691 backend, supports modern packaging standards like PEP 751, and provides CLI commands for auditing vulnerabilities and inspecting dependency trees. The system manages its own vendored dependencies and includes a benchmarking suite to monitor performance regressions.
How it got here
2017–2018 — vendoring infrastructure and CLI migration
16 changes.
This period focused on establishing a robust vendoring system to bundle and patch third-party dependencies, ensuring consistent runtime behavior. Concurrently, the project migrated its command-line interface from Click to argparse and expanded test coverage with comprehensive integration and unit suites to validate these structural changes.
2019–2022 — pip vendoring and modularization
13 changes.
This period focused on updating the vendored pip dependency to version 26.2, incorporating upstream improvements in dependency resolution, network handling, and Python 3.12 compatibility. The project also refactored the monolithic utils module into a modular subsystem to improve maintainability and startup performance, while enhancing test coverage with realistic package fixtures.
2023–2026 — Resolver modernization and tooling expansion
8 changes.
This period focused on decoupling the dependency resolver from patched pip internals by introducing a pure-Python PEP 691 backend with parallel fetching and a pluggable architecture. Concurrently, the project expanded its tooling capabilities through the new pipenv.routines package, added a comprehensive performance benchmark suite, and improved Python environment detection via refactored pythonfinder utilities.
Features
Add pipenv performance benchmark suite
A new benchmarking framework has been added to the \benchmarks\ directory to monitor pipenv performance and prevent regressions. The suite, based on the \python-package-manager-shootout\ project, uses Sentry's real-world dependency set to measure operations such as tooling setup, requirements import, locking, installation (cold and warm cache), updates, and package additions. It provides a runner script (\benchmark.py\) that captures detailed timing, CPU, and memory statistics, supports local profiling via cProfile, and integrates with CI to upload results as artifacts for historical analysis.
benchmarks · high confidence
Added PEP 751 pylock.toml example files
The examples directory now includes a \Pipfile.with\_pylock\ file demonstrating how to enable pylock.toml generation via the \use\_pylock\ setting, alongside a \pylock.toml\ file that serves as a concrete example of the PEP 751 lock file format supported by Pipenv.
examples · high confidence
Automated release and vendoring tasks
The project now includes a new \tasks\ directory containing Invoke-based automation scripts for managing releases and vendored dependencies. This introduces structured workflows for bumping versions, building distribution packages (sdist/wheel) using \python -m build\, generating changelogs via Towncrier, creating git tags, and uploading artifacts to PyPI. It also provides tasks for managing vendored packages and generating documentation manuals, replacing previous ad-hoc or manual release processes.
tasks · high confidence
Introduce pipenv.routines package with RoutineContext scaffolding and new audit command
The pipenv/routines directory has been restructured into a new package containing individual command implementations (audit, check, clean, clear, graph, install, lock, outdated, requirements, scan) and a new context.py module. The context module introduces the RoutineContext dataclass, which bundles CLI inputs (target environment, install policy, package selection, execution options) to standardize how arguments flow through install, update, lock, sync, and uninstall operations. Additionally, a new 'pipenv audit' command has been added, leveraging pip-audit for vulnerability scanning, while existing commands like check and scan continue to support the optional safety dependency.
pipenv/routines · high confidence
Introduce pluggable resolver backend architecture
The resolver now uses a pluggable backend system, starting with the existing pip backend. Users can select a resolver backend via the \\\[pipenv\] resolver\\ section in Pipfile, the \\--resolver\\ CLI flag, or the \\PIPENV\_RESOLVER\\ environment variable. If an unknown or unavailable backend is requested, pipenv fails loudly with an error listing available backends. The default backend remains \\pip\\, and no functional behavior changes for existing users who do not explicitly select a backend.
pipenv/resolver/backends · high confidence
Introduce vendoring task infrastructure for managing patched dependencies
A new vendoring task script has been added to automate the process of downloading, patching, and renaming third-party libraries (such as pip, requests, and urllib3) into the project's internal patched and vendor directories. This tool handles import rewriting to ensure these dependencies are isolated under specific namespaces (e.g., pipenv.patched.pip), applies custom patches to resolve compatibility issues, and manages license file collection, providing a centralized mechanism for maintaining vendored dependencies.
tasks/vendoring · high confidence
Introduces a pure-Python PEP 691 resolver backend with parallel fetching and disk caching
Adds a new, pipenv-owned resolver implementation in \pipenv/resolver\ that replaces the legacy subprocess/argv protocol with a typed JSON wire format (\ResolverRequest\/\ResolverResponse\). This new backend includes a PEP 691 JSON simple-API client (\PEP691Client\), a parallel fetch driver (\ParallelFetcher\) for concurrent index lookups, and a disk-backed manifest cache (\ParsedManifestCache\) with TTL and atomic writes. It also introduces typed data models for candidates and hashes, along with dedicated auth helpers for netrc and URL credentials, decoupling the resolver from patched-pip internals.
pipenv/resolver · high confidence
Pipenv 2026.8.0 introduces sequential scripts, inline environment variables, and a new Environment subsystem
Pipenv 2026.8.0 adds support for sequential command execution in the Pipfile \\[scripts\]\ section using TOML arrays, allowing multiple commands to run in order (stopping at the first failure). It also supports inline environment variable assignments (e.g., \FOO=bar python script.py\) within scripts, automatically extracting and injecting them into the execution environment. The release introduces a new \pipenv.environment.Environment\ subsystem to manage virtual environment paths and package discovery, alongside a new \pipenv.cmdparse.Script\ parser to handle these advanced script formats. Additionally, the version is bumped to 2026.8.0.
pipenv · high confidence
Repository initialization with modern developer tooling and documentation
The repository has been initialized with a comprehensive set of configuration files and documentation to standardize the development workflow. This includes a \.pre-commit-config.yaml\ that enforces code quality using \ruff\ and \pyproject-fmt\, a \.editorconfig\ for consistent indentation across editors, and a \.deepsource.toml\ for static analysis. Documentation is consolidated in \README.md\ and \CONTRIBUTING.md\, with a new \CHANGELOG.md\ tracking changes and a \SECURITY.md\ for vulnerability reporting. Build and release processes are supported by a \Makefile\, \MANIFEST.in\, and \RELEASING.md\, while CI/CD is configured via \.readthedocs.yaml\ and \.github\ workflows. The \get-pipenv.py\ installer script is also included to facilitate easy installation.
(repo-wide) · high confidence
Removals
Removal of pipfile package source code
The pipfile Python package has been removed from the repository. This change deletes the core implementation files, including the API module (PipfileParser, Pipfile classes, and load function), the JSON serialization logic (\json.py), and the package metadata (\\about\\.py and \\init\\_.py). Users relying on this library for parsing Pipfiles will no longer have access to these components.
pipfile · high confidence
Architecture
Refactor pipenv.utils into a modular subsystem
The monolithic pipenv.utils module has been reorganized into a set of focused submodules (constants, dependencies, display, environment, exceptions, fileutils, funktools, indexes, internet, lockfile, locking, markers, pip, pipfile, pylock, requirements, shell, shell\_utils, sources, tomli, unpack, virtualenv). This structural change improves code maintainability and reduces import overhead by deferring heavy pip-internal dependencies until they are actually needed, which speeds up CLI startup time.
pipenv/utils · high confidence
Behavioural changes
Added empty \_\_init\_\_.py to ruamel vendor package
An empty \_\init\\_.py file has been added to the pipenv/vendor/ruamel directory. This change ensures the ruamel directory is recognized as a Python package, which is necessary for proper bundling and import resolution within the vendored dependencies.
pipenv/vendor/ruamel · high confidence
Fix pipdeptree import paths and add ruamel vendoring patch
Updates the vendored pipdeptree to ensure it correctly locates its dependencies by modifying sys.path in \_\main\\.py and switching the tomli import to use the patched pip vendor copy for Python versions below 3.11. Additionally, adds a new patch file for ruamel to handle its \\init\\_.py import structure.
tasks/vendoring/patches/vendor · high confidence
Improved install-scheme resolution with sysconfig fallback
The pipenv-internal pip locations module now prioritizes the standard library's \sysconfig\ for determining package installation paths, while retaining \distutils\ as a fallback for compatibility. Crucially, if \distutils\ is unavailable (as is the case on Python 3.12+ or certain Linux distributions), the system now safely falls back to \sysconfig\ instead of failing, ensuring that package installation schemes are resolved correctly across modern Python versions and diverse platform configurations.
_pipenv/patched/pip/\internal/locations · high confidence
Migrate CLI from Click to argparse
The pipenv command-line interface has been rewritten to use Python's standard argparse library instead of the third-party Click framework. This change introduces new argument parsing infrastructure in pipenv/cli/options.py and a refactored command dispatcher in pipenv/cli/command.py, which now delegates to routine-based implementations (e.g., RoutineContext). For users, this may result in subtle differences in help text formatting, error messages, and argument validation behavior, although the core commands (install, uninstall, lock, etc.) remain functionally equivalent.
pipenv/cli · high confidence
Plette vendor updated to v2.2.1 with strict Pipfile validation
The vendored plette library in pipenv/vendor/plette/models has been updated to version 2.2.1. This update introduces strict validation for Pipfile entries, specifically rejecting any package keys that are not explicitly recognized (such as typos like 'commit' instead of 'ref'). It also adds support for the \[pipenv\] section in Pipfile, including validation for the 'cool-down-period' configuration option.
pipenv/vendor/plette/models · high confidence
Python version information model refactored to use dataclass
The internal model for storing Python version information has been replaced with a new \PythonInfo\ dataclass. This change simplifies the data structure by replacing the previous complex class, providing explicit fields for version components (major, minor, patch), release types (prerelease, postrelease, dev, debug), and architecture. It introduces new capabilities for matching Python installations against specific criteria (version, architecture, debug mode) and includes robust sorting logic to order Python versions correctly, which improves how pipenv identifies and selects available Python interpreters.
pipenv/vendor/pythonfinder/models · high confidence
Refactored pythonfinder utility modules for improved path and version handling
The vendored pythonfinder library has been updated with new utility modules (\path\_utils.py\ and \version\_utils.py\) that replace previous implementations. This change introduces more robust path resolution logic, including better handling of environment variables and Windows-specific path normalization, and enhances Python version parsing to support PEP 514 metadata and various version formats (including pyenv and asdf). Users benefit from more reliable detection of Python installations and fewer errors when resolving paths on restricted or non-standard systems.
pipenv/vendor/pythonfinder/utils · high confidence
Updated vendored pip patches for compatibility, safety, and resolution fixes
This update refreshes the vendored pip patches to support newer pip versions and address several compatibility and security issues. It adds a fallback to sysconfig when distutils is missing (Python 3.12+), fixes editable VCS extras handling, and corrects wheel name casing to preserve original directory structures. The resolver now tolerates missing upload times and allows prerelease fallback when no final releases match. A new patch enforces stricter tarfile link-target validation to prevent path traversal vulnerabilities ([GHSA redacted]). Additionally, it introduces an ignore-compatibility flag for package finding, restricts index lookups to project-specific URLs, and resolves circular import issues in progress bars.
tasks/vendoring/patches/patched · high confidence
Updated vendored python-dotenv to version 1.2.2
The vendored python-dotenv library in pipenv/vendor/dotenv has been updated to version 1.2.2. This update includes a new IPython magic command (%dotenv) for loading environment files directly within IPython sessions, improved parsing logic for .env files with better handling of escape sequences and variable interpolation, and the addition of type hints (PEP 561) to support static type checking.
pipenv/vendor/dotenv · high confidence
Vendor pip 26.2 and update pipenv's internal requirement handling
This update vendors pip version 26.2 into pipenv's patched directory, bringing in the latest requirement resolution and installation logic. The changes in the \pip/\_internal/req\ module include new support for PEP 723 script metadata parsing, dependency group resolution via \pyproject.toml\, and refined handling of editable VCS requirements and extras. Users benefit from improved compatibility with modern Python packaging standards and more robust installation processes for editable and version-controlled dependencies.
_pipenv/patched/pip/\internal/req · high confidence
Vendored packaging library updated to version 26.2
The vendored copy of the packaging library in pipenv/vendor/packaging has been updated to version 26.2. This update introduces new capabilities for parsing ELF files to better detect Linux runtime environments (glibc and musl versions), adds support for PEP 735 dependency groups, and includes a new module for canonicalizing SPDX license expressions. These changes improve the accuracy of platform compatibility checks and expand the library's ability to handle modern Python packaging standards.
(repo-wide) · high confidence
Vendored pip network layer updated to pip 26.2
The network handling module in the vendored pip copy (pipenv/patched/pip/\_internal/network) has been updated to the pip 26.2 release. This brings in the latest network utilities, authentication helpers, session management, and download logic from the upstream pip project, ensuring that pipenv's internal package installation and network request behavior aligns with the current pip standards.
_pipenv/patched/pip/\internal/network · high confidence
Vendored pip resolution engine updated to pip 26.2
The vendored copy of pip's resolution engine (pipenv/patched/pip/\_internal/resolution/resolvelib) has been updated to pip 26.2. This brings in the latest resolver logic, including improved handling of dependency conflicts, better error reporting for resolution failures, and fixes for edge cases involving uncanonical package names and Python version filtering. Users will benefit from more accurate dependency resolution and clearer error messages when conflicts arise.
_pipenv/patched/pip/\internal/resolution/resolvelib · high confidence
Vendored pip to version 26.2
The vendored copy of pip in pipenv has been updated to version 26.2. This brings the latest command-line interface improvements, including enhanced shell autocompletion for subcommands and options, updated progress bar rendering using Rich, and refined error handling and logging behavior within the CLI entry points.
_pipenv/patched/pip/\internal/cli · high confidence
Vendored pip updated to version 26.2
The internal copy of pip used by Pipenv has been updated to version 26.2. This brings the latest command implementations, dependency resolution logic, and bug fixes from the upstream pip project into the environment management tool.
_pipenv/patched/pip/\internal/commands · high confidence
Vendored pipdeptree upgraded with new programmatic API and offline resolution subcommands
The vendored pipdeptree library has been updated to a newer version that introduces a programmatic Python API (pipenv.vendor.pipdeptree.render) for generating dependency trees in notebooks, adds CLI subcommands to resolve dependencies from a package index (--from-index) or a PEP 751 lock file (--from-lock) without inspecting the active environment, and improves virtual environment detection for Poetry and Conda.
pipenv/vendor/pipdeptree · high confidence
Fixes
Refactored Python finder architecture with PEP 514 and Windows py-launcher fixes
The Python finder logic in pipenv/vendor/pythonfinder/finders has been restructured into a modular class hierarchy (BaseFinder, PathFinder, and specific finders for asdf, pyenv, system PATH, Windows registry, and the Windows py launcher). This refactor introduces support for PEP 514 registry lookups on Windows and fixes full-version matching for the py launcher, ensuring that specific patch versions (e.g., 3.11.9) are correctly identified rather than just major.minor. Additionally, the SystemFinder now gracefully handles PermissionErrors on Windows restricted PATH entries during virtual environment resolution, preventing crashes when resolving paths in protected directories.
pipenv/vendor/pythonfinder/finders · high confidence
Test coverage
Add Git submodule references for test artifacts; Added frozen PyPI simple-API test fixtures for PEP 691 and PEP 503; Added test fixtures for Cython and legacy backend packages; Added test fixtures for fake and legacy backend packages; Expanded unit test coverage for resolver, credential safety, and routine context routing; New integration test suite for pipenv; Test infrastructure updates and fixture initialization.
Dependencies
Introduce vendored dependency management infrastructure
Pipenv now includes a new \vendor/\ directory structure to manage bundled third-party libraries, starting with \python-dotenv\, \pythonfinder\, \plette\, \tomlkit\, \shellingham\, \pexpect\, \ptyprocess\, \pipdeptree\, and \packaging\. This change introduces a Makefile and a \vendor.txt\ manifest to automate the downloading and syncing of these dependencies, aiming to reduce external runtime dependencies and ensure consistent behavior across environments.
pipenv/vendor · high confidence
Update dependency versions and lockfiles across project directories
This change updates the pinned versions of core and development dependencies in the root Pipfile, examples Pipfile, and docs requirements.txt, alongside regenerating the corresponding lockfiles to ensure reproducible builds. Key version bumps include urllib3 to \>=2.7.0, requests to \>=2.32.0, and Sphinx to \>=8.1.3 in the documentation requirements, while the root environment now requires virtualenv \>=20.26.6 and setuptools \>=67. The legacy requirements.txt file has been removed as the project migrates to Pipfile-based dependency management.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 66.
Lenses
- Code Health 85
- Architecture 99
- Maturity 61
- Readiness 58
- Security 83
Changes since last survey
- 300 commits — 233 feature/other, 67 fixes
By area
- docs/dev — 62 commits
- pipenv/utils — 38 commits
- (root) — 37 commits
- (repo) — 33 commits
- tests/unit — 27 commits
- pipenv/resolver — 22 commits
- pipenv/routines — 22 commits
- tests/integration — 9 commits
- pipenv/version.py — 8 commits
- pipenv/patched — 7 commits
- docs/pipfile.md — 3 commits
- news/+initiative-a-is-valid-url.removal.rst — 3 commits
- pipenv/cli — 3 commits
- pipenv/project.py — 3 commits
- .github/workflows — 2 commits
- docs/cli.md — 2 commits
- pipenv/vendor — 2 commits
- docs/shell.md — 1 commit
- examples/Pipfile — 1 commit
- examples/Pipfile.lock — 1 commit
Notable commits
- fix: Fix Pipfile script expansion for PIPENV_PROJECT_DIR (#6655)
- fix: Fix Plette Pipfile attribute delegation
- fix: Fix _target_marker_environment to return None when allow_global=True
- fix: Fix audit --locked with Pipfile.lock and legacy shell completion env var
- fix: Fix corrupt lockfile recovery return
- fix: Fix editable VCS extras with pip 26.2
- fix: Fix first-party CodeQL reliability errors
- fix: Fix host package leakage into project installs
- fix: Fix latest hash and virtualenv guidance issues
- fix: Fix pipenv shell breaking terminal input echo (#6636)
- fix: Fix ruff I001 import ordering in install.py
- fix: Merge pull request #6648 from pypa/fix/issues-6641-6645-6647
- fix: Merge pull request #6671 from pypa/fix/6670-env-var-source-url-auth
- fix: Merge pull request #6675 from pypa/fix/6672-update-relock-when-no-packages
- fix: Merge pull request #6688 from dchaudhari7177/fix/major-only-python-version
- fix: Merge pull request #6692 from pypa/fix/post-release-issues-2026-08
- fix: Merge pull request #6695 from pypa/fix/release-pipeline-recovery-2026-08
- fix: Merge pull request #6700 from pypa/fix/locked-transitive-install
- fix: Merge pull request #6703 from matteius/fix/6701-prerelease-lower-bound
- fix: Merge pull request #6713 from pypa/fix/issues-6704-6712
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
pypa/pipenv was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3f1b272abd51d7d7ab7f5935bb6b25da86e93e8b — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.