PyPI dependencies

PyPI dependency declarations, releases, downloads, and OSV summaries

This Actor reads PyPI JSON for packages you list and emits dependency declarations, release cadence, maintainer hints, download stats, and OSV summaries. Python/PyPI only.

Not npm trees. Not legal advice. Informational package metadata only.

from $3.00 / 1,000 PyPI package or dependency row ($0.003 per delivered apify-default-dataset-item). No Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

Open PyPI Package & Dependency Scraper on Apify

PyPI Package & Dependency Scraper, not a neighboring Actor

Use this page for this Actor’s job. Use PyPI Vulnerability Scraper for PyPI + OSV package alerts; Use npm Package & Dependency Scraper for npm deps/versions; Use OSS Vulnerability Monitor for OSV/GitHub advisories.

This ActorPyPI Vulnerability Scrapernpm Package & Dependency ScraperOSS Vulnerability Monitor
Intent PyPI Package & Dependency ScraperPyPI + OSV package alertsnpm deps/versionsOSV/GitHub advisories
Primary input see schemapackagespackagespackages
What it reads Public sources listed on the Store pagePyPI + OSVnpm registryOSV + GitHub Advisories
Primary output Dataset rows billed per live PPEPyPI package rowsnpm dep rowsvuln rows
Not this job Not npm trees. Not legal advice. Informational package metadata only.Not npm registry metadataNot license-policy auditsNot license-policy trees

Store ID: taroyamada/pypi-package-dependency-intelligence. Respect source terms, robots.txt, and rate limits.

Use cases

How is PyPI Package & Dependency Scraper different from PyPI Vulnerability Scraper and npm Package & Dependency Scraper?

PyPI Package & Dependency Scraper (taroyamada/pypi-package-dependency-intelligence): This Actor reads PyPI JSON for packages you list and emits dependency declarations, release cadence, maintainer hints, download stats, and OSV summaries. Python/PyPI only. Not npm trees. Not legal advice. Informational package metadata only. PyPI Vulnerability Scraper is for PyPI + OSV package alerts (input packages; PyPI + OSV; PyPI package rows). Not npm registry metadata. npm Package & Dependency Scraper is for npm deps/versions (input packages; npm registry; npm dep rows). Not license-policy audits. OSS Vulnerability Monitor is for OSV/GitHub advisories (input packages; OSV + GitHub Advisories; vuln rows). Not license-policy trees.

What input is required?

Live required fields: packages. Published exampleRunInput is shown below. Fetch official PyPI JSON API data and export package summaries, release cadence rows, dependency declarations, maintainer hints, download stats, and vulnerability signals.

Field Type Default Notes
packages any[] required empty required Package Names. PyPI package names to fetch from the official JSON API. Use names such as requests, fastapi, pandas, django, or numpy.
includeReleaseHistory boolean true Include Release Rows. When true, writes one release_version row per version in addition to the package summary and dependency rows.
includeDownloadStats boolean false Include Download Stats. Fetch recent package download counts from pypistats.org. Warnings are returned if the enrichment is unavailable.
includeVulnerabilities boolean false Include OSV Vulnerability Summary. Query OSV for known advisories for each package. Results are advisory summaries, not a complete security audit.
maxReleaseRowsPerPackage integer 100 Max Release Rows Per Package. Maximum release_version rows to emit per package when release rows are enabled. min=1 max=1000
maxDependencyRowsPerPackage integer 250 Max Dependency Rows Per Package. Maximum dependency rows to emit per package. min=1 max=1000
concurrency integer 5 Concurrency. Number of packages to fetch in parallel. min=1 max=10
timeoutMs integer 15000 Request Timeout (ms). Per-request timeout in milliseconds. min=1000 max=30000
delivery string enum dataset Delivery. Send flattened rows to the dataset or POST the full payload to a webhook. enum: dataset, webhook
webhookUrl string empty Webhook URL. Required when delivery is webhook.
dryRun boolean false Dry Run. Run without saving dataset rows or sending a webhook.

Published Store example run input (omitted fields take schema defaults):

{
  "packages": [
    "requests",
    "numpy"
  ],
  "includeReleaseHistory": true,
  "includeDownloadStats": false,
  "includeVulnerabilities": false,
  "concurrency": 5,
  "timeoutMs": 15000,
  "delivery": "dataset",
  "dryRun": false
}

Run PyPI Package & Dependency Scraper on Apify

How do dataset, webhook, and dry-run delivery work?

delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

What does a result contain?

Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.

How is PyPI Package & Dependency Scraper priced?

Billing is pay per event. The live Store card is from $3.00 / 1,000 PyPI package or dependency row ($0.003 per delivered apify-default-dataset-item). No Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:

Event Price Emitted when
apify-default-dataset-item (PyPI package or dependency row) $0.003 Charged for one delivered PyPI package, release, or dependency row.

from $3.00 / 1,000 PyPI package or dependency row ($0.003 per delivered apify-default-dataset-item). No Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

See PyPI Package & Dependency Scraper pricing on Apify

Limits to keep in mind

Open PyPI Package & Dependency Scraper on Apify

Related pages