nab

nab resolves Python project dependencies and writes a PEP 751 lock or pinned requirements. It can download resolved artifacts, but it does not install them.

Keep dependency ranges in pyproject.toml, use nab to select compatible versions, then review the lock before handing it to an installer. The lock includes transitive dependencies and records its target environments. Installing from it reuses the recorded selection; running nab again makes a fresh one.

Start with the Python and platform running nab, declare a deployment target, or lock a matrix of environments. Remote sources are read without building them by default; build policy controls when a backend may run.

Start with a task

Status

nab is experimental. The table below states the current boundary; feature pages carry their own stability warnings.

Area

Current boundary

Runtime

CPython 3.10 and newer. Other interpreters are not tested.

Commands

nab lock resolves and writes a lock. nab download resolves again and fetches artifacts. Neither command installs packages.

Sources

Simple indexes, local checkouts, declared git sources, hash-pinned .tar.gz archives, and workspace members. Project-root name @ git+... requirements are not resolved yet.

Output

PEP 751 pylock.toml, requirements with recorded index hashes, and requirements without those hashes.

Experimental features

Universal locks, multiple indexes, and workspaces. Their feature pages state the current boundary.

Embedding

nab-resolver has a path-stable public API. nab-markersets documents its supported surface but remains experimental; the other component APIs are experimental.

Tutorial

Project