NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4168 most downloaded on PyPI
Identify unused dependencies and avoid a bloated virtual environment.
Last release 6 months ago
28 Mar 2026
Release timing varies
gaps range from 9 days to 6 months
Nearly every release is documented
notes for 42 of 44 stable releases
1 version withdrawn
withdrawn after publishing
5 years old
48 releases · first in 2022
One column per quarter.
## 5.2.0 (2026-03-28) ### Features * detect redundant excludes
django: improve resolution, variable mutation tracking
add --include-deferred flag to detect imports inside functions (#373) (570ca77), closes #372
handle single PEP 735 dependency group in section path
Python 3.9 is no longer supported as it has reached end-of-life. The minimum required version is now Python 3.10.
contrib: mention python versions
ignore missing deps sections with warning
## 4.0.3 (2025-04-10) ### Bug Fixes * poetry: support list
version suffix not supported by regexp
support dependency spec where version can either be str or dict
python: drop python 3.8 support
This is the last release before dropping Python 3.8 support.
This is the last release before dropping Python 3.8 support.
uv (https://github.com/fredrikaverpil/creosote/pull/262/commits/71aa48ecf990cf01c4f1e9f5704dff365aa0f8fc)pyproject.toml, read version string from package metadata (https://github.com/fredrikaverpil/creosote/pull/262/commits/8bc460038530c0a0817974138d4f519c5c287ca3)hatchling (https://github.com/fredrikaverpil/creosote/pull/262/commits/855a24039868f6c6a65b6c169a429c8eb982927b)typing-extensions dependency (https://github.com/fredrikaverpil/creosote/pull/262/commits/970014b3a8ff01da6ab7ec8ee029b170df3ebb3c)parser: add PEP-735 support for dependency-groups
compare using canonicalization (#222) (0002145), closes #205
Support for Jupyter notebook (*.ipynb) files (#217) - thank you @pmason314 ❤️
Support non-UTF8 files and show warnings when parsing Python 2.x code. #209
pyproject.toml) is not found. #212ruamel.yaml not properly detected due to lack of support of period signs in dependency name #206
ruamel.yaml not properly detected due to lack of support of period signs in dependency name #206Some CLI arguments have been renamed.
For exact details on the CLI argument changes, see the migration guide (attached at the bottom of these release notes and in the README).
pyproject.toml (❤️🙏 @BrianPugh #183 hacktoberfest-accepted). See the README for more details.Creosote was updated to 3.0.0 because the way arguments were supplied has now changed. This also brings pyproject.toml configuration support.
The argument naming has changed:
| 2.x argument name | 3.x argument name |
|---|---|
--exclude-deps |
--exclude-dep |
--paths |
--path |
--sections |
--section |
With creosote 2.x, you were able to provide multiple values following some arguments, example:
creosote -p file1.py file2.py
With creosote 3.x, you must now provide multiple arguments as a key/value pair:
creosote -p file1.py -p file2.py
This new creosote 3.x behavior applies to the following 3.x CLI arguments:
--venv--exclude-dep-p or --path-s or --sectionBugfix for when using Pipfile #174
Pipfile #174Fixes a problem for PEP-582 / PDM users, who would like to point their venv to the __pypackages__ folder. Although PEP-582 was rejected, this is very
__pypackages__ folder. Although PEP-582 was rejected, this is very easy to support right now. As long as this is easy to support, I see no issue with supporting PEP-582 and __pypackages__. #171Bumped Loguru dependency to support 0.7.0.
The venv's RECORD file was read _only_ if no top_level.txt file was found in the venv. This behavior has changed, so that both the top_level.txt and R
RECORD file was read only if no top_level.txt file was found in the venv. This behavior has changed, so that both the top_level.txt and RECORD files are always read now. This is done to simply increase the chance to find a correlation between the dependency name and its import name.distlib.database to read the RECORD file. This code was cleaned up and the dependency on distlib has been removed.`bash pip install --pre creosote==2.6.0rc1 `
pip install --pre creosote==2.6.0rc1
top_level.txt file for the dependency's import name, creosote used to check the venv's RECORD file, using distlib.database. This code was cleaned up a bit, and the dependency of distlib was removed.top_level.txt file (for the given dependency) was found, the RECORD file check was not performed in Creosote 2.5.0. In this release this behavior is changed and the RECORD file check is always being performed. The reason for doing this is simply to increase the chances of finding the dependency's import name.distlib was removed.Previous to (and including) this release, you could specify --venv . which will then attempt to scan through any virtual environments (or actually sit
--venv . which will then attempt to scan through any virtual environments (or actually site-packages) locations you might have in the current directory. But with this release you can also specify the --venv argument multiple times, so to specify virtual environments in different locations. This should also support containerized installations, where you point --venv to a site-packages location.creosote -v .venv -v other-venv
v3-args is introduced. This is an experimental feature which entails backwards compatibility breaking functionality and might or might not make it into Creosote v3.0.0. This particular feature changes the arguments definitions, so that instead of defining e.g. --paths <path1> <path2>, you will now define this using multiple declarations of --path, like so:--path <path1> --path <path2>
Enable with --use-feature v3-args to try it out. Please give feedback if you have any thoughts around this!
Added the optional command line argument --use-feature, which can be used to enable experimental features. Specify --use-feature fail-excluded-and-not
--use-feature, which can be used to enable experimental features. Specify --use-feature fail-excluded-and-not-installed to have Creosote exit with error code 1 if an excluded dependency is not found in the dependency specification file (e.g. pyproject.toml).Adds the --exclude-deps argument which takes one or more dependencies you wish to exclude from the scan. #142
--exclude-deps argument which takes one or more dependencies you wish to exclude from the scan. #142Fixes #145 where Creosote did not use an exit code of 1 when detecting unused packages.
Don't call distlib.database, for package name → import name lookup, if import name was found in top_level.txt. #139
distlib.database, for package name → import name lookup, if import name was found in top_level.txt. #139Make all open() calls use UTF-8 encoding #136
open() calls use UTF-8 encoding #136--verbose.Log the command arguments when supplying the --verbose flag.
--verbose flag.Log the creosote version and the command issued, as part of the log output when specifying --verbose.
--verbose.This release more clearly formalize the three strategies used to figure out the import/module naming based on the package name. Solves #123 partly, wh
typing-extensions package was not properly associated with the typing_extensions import name.Log the version of Creosote when using the --verbose argument.
--verbose argument.Fixes a glob issue, where the path leading up to the top_level.txt file (containing the import name of the package) was case sensitive. This resulted
glob issue, where the path leading up to the top_level.txt file (containing the import name of the package) was case sensitive. This resulted in that e.g. gitpython, which has a path of .venv/lib/python3.11/site-packages/GitPython-3.1.30.dist-info/top_level.txt was not detected, and the import of git (from inside that file) could not be read.--verbose argument.Added support for pipenv/Pipfile.
--verbose argument is given.Improve requirements.txt parsing by leveraging pip-requirements-parser. Enables parsing of editable requirements. ❤️ @elijahr #121
requirements.txt parsing by leveraging pip-requirements-parser. Enables parsing of editable requirements. ❤️ @elijahr #121top_level.txt file globbing #121Fixes bug https://github.com/fredrikaverpil/creosote/pull/120
Support for direct references (git links).
Internal:
Remove "Development Status :: 4 - Beta" from package classifiers.
Backwards-breaking change: remove the -d (--dev) flag.
-d (--dev) flag.-s (--sections) for greater control over toml sections to parse.requirements.txt|in-type files.Minor internal improvements:
.pyton-version to use minimum supported Python version (3.7).Replaced the Poetry build system with the Hatchling build system.
Please note that no functional changes where done to creosote and that this release contains purely internal changes.
Nothing published for this version
- Added pypi details - Use Poetry 1.1.13 in CI
Nothing published for this version
Nothing published for this version
Nothing published for this version
Ready to be tested in the wild!
Your coding agent can read these notes before it upgrades. Set up the MCP server →