惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
Vercel News
Vercel News
Recent Announcements
Recent Announcements
B
Blog RSS Feed
Y
Y Combinator Blog
M
MIT News - Artificial intelligence
MongoDB | Blog
MongoDB | Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
雷峰网
雷峰网
D
Docker
Jina AI
Jina AI
IT之家
IT之家
人人都是产品经理
人人都是产品经理
L
LangChain Blog
G
Google Developers Blog
Google DeepMind News
Google DeepMind News
MyScale Blog
MyScale Blog
博客园 - 叶小钗
The GitHub Blog
The GitHub Blog
The Cloudflare Blog
A
About on SuperTechFans
Hugging Face - Blog
Hugging Face - Blog

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - think41/extrasuite: Token-efficient pull/edit/push workflow for AI agents editing Google Workspace files (Sheets, Docs, Slides, Forms) GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw
GitHub - sshiraz/depsly: Dependency risk analysis tool fo...
2026-04-12 · via Hacker News: Show HN

Depsly is a local-first dependency decision CLI for JavaScript/TypeScript projects.

It helps you answer:

  • What dependencies actually matter?
  • What should I review first?
  • Why is this transitive package even here?
  • What happens if I remove something?

🧠 Why Depsly

Most dependency tools focus on:

  • vulnerabilities
  • compliance
  • audit reports

Depsly focuses on:

Decision-making

It combines:

  • dependency graph analysis
  • structural impact simulation
  • feasibility-aware recommendations
  • saved scan history and comparison

So you can decide where to spend your time.


✨ What Depsly Does

  • Builds a full dependency graph from package-lock.json
  • Analyzes structural risk (depth, fanout, transitive exposure)
  • Ranks dependencies by impact × actionability
  • Explains why transitive dependencies exist
  • Simulates structural impact of removing packages
  • Exports normalized recommendation scans as JSON
  • Saves scans locally for history and comparison
  • Generates an interactive HTML dependency explorer with tree, path, and graph views
  • Runs entirely locally (no code upload required)

⚡ Install

Recommended (pipx)

If needed:

pipx install --python python3.11 depsly

Alternative (pip)


🚀 Quick Start

Analyze your dependency graph

depsly analyze package-lock.json

JSON export:

depsly analyze package-lock.json --json

Get prioritized recommendations

depsly recommend package-lock.json

JSON export:

depsly recommend package-lock.json --json

Trace why a package exists

depsly trace package-lock.json @babel/core@7.29.0

JSON export:

depsly trace package-lock.json @babel/core@7.29.0 --json

Preview structural impact of removal

depsly simulate-remove package-lock.json eslint@9.39.4

JSON export:

depsly simulate-remove package-lock.json eslint@9.39.4 --json

Save and compare scans over time

depsly save-scan package-lock.json
depsly list-scans --project frontend
depsly compare-scans ~/.depsly/scans/frontend-2026-04-11T10-15-43Z.json ~/.depsly/scans/frontend-2026-04-12T09-20-00Z.json

Open the dependency graph in your browser

depsly graph-html package-lock.json

The HTML report now opens in an Explorer-first surface:

  • Explorer view for a readable collapsible dependency tree
  • Graph view for neighborhood or full-graph relationship inspection
  • Path from root in the sidebar to explain why a package exists
  • Search, keyboard pan/zoom, and box-zoom controls for graph inspection

🧪 Example Output

Depsly Recommendations
Project: frontend
Packages analyzed: 204

1. eslint@9.39.4
   Action: REVIEW
   Actionability: MEDIUM
   Reason confidence: HIGH
   Impact: 35%
   Classification: Direct (root dev dependency)

   Why:
     - Direct dependency from root devDependencies
     - Structural impact: 35% (71 packages). Verify whether this dependency is still required

🧭 How to Read the Output

Action

What Depsly suggests:

  • REVIEW → investigate before changing
  • REMOVE → strong candidate to remove
  • TRACE_UPSTREAM → change parent dependency instead
  • DEFER → low priority

Actionability

How easy it is to change:

  • HIGH → easy to modify
  • MEDIUM → moderate effort
  • LOW → difficult or risky

Impact

Percentage of your dependency graph affected.


Reason confidence

How strong the structural signal is:

  • HIGH → direct + clear signals
  • MEDIUM → inferred from structure
  • LOW → limited information

🔁 Typical Workflow

analyze → recommend → trace → simulate-remove
                 ↓
              save-scan → list-scans → compare-scans
                 ↓
              graph-html

⚠️ Important

Structural analysis only.
Does not guarantee install, build, or runtime correctness.


🔐 Why Local-First Matters

  • No source code upload
  • No account required
  • No rate limits
  • Fully deterministic

🎯 Philosophy

Depsly is not a scanner.

It is a:

Dependency decision support system


📚 Docs

Run the CLI help to explore all commands and options:

For command-specific help:

depsly analyze --help
depsly recommend --help
depsly trace --help
depsly simulate-remove --help
depsly save-scan --help
depsly list-scans --help
depsly compare-scans --help
depsly graph-html --help

Example:

depsly recommend package-lock.json

🚧 Status

Early release (v0.1.11)

Core features are stable:

  • analyze
  • analyze --json
  • recommend
  • recommend --json
  • trace
  • trace --json
  • simulate-remove
  • simulate-remove --json
  • save-scan
  • list-scans
  • compare-scans
  • graph-html Explorer-first HTML report with collapsible tree, path view, and neighborhood graph
  • telemetry Opt-in anonymous command-level usage telemetry with local queueing, batch flush, and reference ingest/reporting tooling
  • scripts/scan_repos.py batch workflow

💬 Feedback

If you try Depsly on your project, I’d love to hear:

  • what felt useful
  • what felt off
  • what you expected but didn’t see

Email: info+depsly@convologix.com or open an issue on GitHub: https://github.com/sshiraz/depsly

Even a quick note or screenshot is incredibly helpful.

I read every message.


🏁 Summary

Depsly helps you move from:

“I have 200 dependencies…”

to:

“Here’s exactly what I should look at first.”