{"package":"gitpython","ecosystem":"pypi","latest_version":"3.1.62","description":"GitPython is a Python library used to interact with Git repositories","license":"BSD-3-Clause","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://github.com/gitpython-developers/GitPython","repository":"https://github.com/gitpython-developers/GitPython","downloads_weekly":35186941,"health":{"score":92,"risk":"low","breakdown":{"maintenance":25,"popularity":20,"security":25,"maturity":15,"community":7,"popularity_floor":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":0,"critical":0,"high":0,"medium":0,"low":0,"details":[]},"versions":{"latest":"3.1.62","total_count":115,"recent":["3.1.43","3.1.44","3.1.45","3.1.46","3.1.47","3.1.48","3.1.49","3.1.50","3.1.51","3.1.52","3.1.53","3.1.54","3.1.55","3.1.56","3.1.57","3.1.58","3.1.59","3.1.60","3.1.61","3.1.62"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":1,"first_published":null,"last_published":"2026-09-07T02:57:19.762833Z","dependencies_count":17,"dependencies":["gitdb<5,>=4.0.1","typing-extensions>=3.10.0.2; python_version < \"3.10\"","coverage[toml]; extra == \"test\"","basedpyright==1.39.9; (python_version >= \"3.9\" and sys_platform != \"cygwin\") and extra == \"test\"","ddt!=1.4.3,>=1.1.1; extra == \"test\"","mock; python_version < \"3.8\" and extra == \"test\"","mypy==1.18.2; python_version >= \"3.9\" and extra == \"test\"","pre-commit; extra == \"test\"","pytest>=7.3.1; extra == \"test\"","pytest-cov; extra == \"test\"","pytest-instafail; extra == \"test\"","pytest-mock; extra == \"test\"","pytest-sugar; extra == \"test\"","typing-extensions; python_version < \"3.11\" and extra == \"test\"","sphinx<8,>=7.4.7; extra == \"doc\"","sphinx_rtd_theme; extra == \"doc\"","sphinx-autodoc-typehints; extra == \"doc\""]},"github_stats":{"stars":5112,"forks":977,"open_issues":188,"is_archived":false,"pushed_at":"2026-04-29T00:31:23+00:00"},"bundle":null,"typescript":null,"known_issues":{"bugs_count":10,"bugs_severity":{"high":2,"medium":6,"critical":2},"status_breakdown":{"fixed":10},"link":"/api/bugs/pypi/gitpython?version=3.1.62","scope":"version","details":[{"title":"GitPython untrusted search path on Windows systems leading to arbitrary code execution","severity":"high","status":"fixed","affected_version":null,"fixed_version":"3.1.33","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wfm5-v35h-vwf4"},{"title":"Untrusted search path under some conditions on Windows allows arbitrary code execution","severity":"high","status":"fixed","affected_version":null,"fixed_version":"3.1.41","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2mqj-m65w-jghx"},{"title":"PYSEC-2024-4: advisory","severity":"medium","status":"fixed","affected_version":null,"fixed_version":"ef3192cc414f2fd9978908454f6fd95243784c7f","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2mqj-m65w-jghx"},{"title":"PYSEC-2023-165: advisory","severity":"medium","status":"fixed","affected_version":null,"fixed_version":"3.1.35","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-cwvm-v4w8-q58c"},{"title":"PYSEC-2023-161: advisory","severity":"medium","status":"fixed","affected_version":null,"fixed_version":"3.1.33","url":"https://docs.python.org/3/library/subprocess.html#popen-constructor"}]},"historical_compromise":null,"recommendation":{"action":"safe_to_use","issues":[],"use_version":"3.1.62","version_hint":null,"summary":"gitpython@3.1.62 is safe to use (health: 92/100)"},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/pypi/gitpython","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/pypi/gitpython","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/pypi/gitpython","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate"},"_cache":"hit","_response_ms":0}