Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Introduction

deps-lsp is a universal Language Server Protocol server for dependency management. A single binary provides hover, completion, diagnostics, code actions, code lens, and inlay hints for outdated, unknown, yanked, vulnerable, and unsatisfiable dependencies across 14 package ecosystems — Cargo, npm, Deno, PyPI, Go, Bundler, Dart, Maven, Gradle, Swift, Composer, NuGet, GitHub Actions, and GitLab CI/CD — instead of requiring a separate extension per language.

A companion binary, deps-cli, runs the same checks from the command line — routing every manifest through the identical classification pipeline — for CI pipelines, pre-commit hooks, and shell scripts where an editor isn’t involved. A ready-made GitHub Action wraps it for CI with zero setup beyond a workflow file.

For installation, editor setup, and LSP configuration options, see the root README.md. This book does not duplicate that material; it covers instead:

Note: API documentation generated from the Rust source (cargo doc) is published separately — see API Documentation.

Supported Ecosystems

EcosystemLanguageManifest File(s)Lock File(s)Highlights
CargoRustCargo.tomlCargo.lockHover, inlay hints, completion, code actions, diagnostics, code lens, feature flag completion, alternate/private registry resolution via .cargo/config.toml
npmJavaScript/TypeScriptpackage.jsonpackage-lock.json, pnpm-lock.yamlHover, inlay hints, completion, code actions, diagnostics, code lens, custom/private registry resolution via .npmrc, pnpm workspace catalog (catalog:/catalog:<name>) resolution via pnpm-workspace.yaml
PyPIPythonpyproject.toml, requirements.txt, constraints.txt (also recognized under a requirements/ directory, e.g. requirements/base.txt)poetry.lock, uv.lockHover with PEP 508 environment marker display (“Active when: <marker>”), inlay hints, completion, code actions, diagnostics, code lens, document links for -r/-c/--requirement/--constraint file references, private/custom index resolution via --index-url/--extra-index-url, Poetry [[tool.poetry.source]], and uv [tool.uv.index]/[tool.uv.sources]
GoGogo.modgo.sumHover, inlay hints, completion, code actions, diagnostics, code lens, pseudo-version support, $GOENV GOPROXY/GOPRIVATE proxy-chain resolution
BundlerRubyGemfileGemfile.lockHover, inlay hints, completion, code actions, diagnostics, code lens, custom-source classification (source/git/path blocks and per-gem options, modern and legacy hash-rocket syntax)
DartDartpubspec.yamlpubspec.lockHover with corrected version ordering (prereleases sort below base release), inlay hints, completion, code actions, diagnostics, code lens, YAML anchor/alias resolution for whole dependency sections and environment:, hosted: custom-registry classification
MavenJavapom.xmlmaven-metadata.xml (CDN)Hover with corrected version ordering (numeric segments outrank qualifiers, prereleases sort below base release), inlay hints, completion, code actions, diagnostics, code lens (property-versioned dependencies not covered)
GradleKotlin/Groovybuild.gradle, build.gradle.kts, gradle/libs.versions.toml—Hover with corrected version ordering (same as Maven), inlay hints, completion, code actions, diagnostics, code lens (variable/catalog-versioned dependencies not covered), variable resolution (gradle.properties)
ComposerPHPcomposer.jsoncomposer.lockHover, inlay hints, completion, code actions, diagnostics, code lens (requirement matching and “latest version” selection both use corrected stability-qualifier ordering)
SwiftSwiftPackage.swiftPackage.resolvedHover, inlay hints, completion, code actions, diagnostics, code lens (range-form dependencies not covered), GitHub API support
NuGet.NET.csproj, .fsproj, .vbproj, Directory.Packages.props, packages.configpackages.lock.json, packages.<project>.lock.json (multi-project)Hover, inlay hints, completion, code actions, diagnostics, code lens, central package management support, SemVer2 prerelease handling, hover-only unlisted-version marker, private/custom feed resolution via NuGet.Config
DenoJavaScript/TypeScript (Deno runtime)deno.json, deno.jsonc— (no deno.lock support yet)Hover, inlay hints, completion, code actions, diagnostics, code lens — jsr: specifiers via the keyless JSR API, npm: specifiers delegate to the same registry client npm uses; imports map only, scopes/importMap not covered
GitHub ActionsYAML.github/workflows/*.yml, *.yaml; action.yml, action.yaml (composite/Docker/JS actions — a repository root or .github/actions/<name>/, issue #706)— (no lock file)Hover, inlay hints, code actions, diagnostics, code lens (package-name completion not covered); tag/commit-SHA/branch uses: pins via the GitHub tags API; reusable-workflow calls recognized but not version-resolved; release-age hint and cooldown diagnostic require GITHUB_TOKEN
GitLab CI/CDYAML.gitlab-ci.yml, .gitlab/ci/*.yml, *.yaml— (no lock file)Hover, inlay hints, code actions, diagnostics, code lens (package-name completion not covered); project:+ref: pins via the GitLab repository-tags API, component: CI/CD Catalog pins via the GitLab project-releases API (SHA/exact-release/~latest/partial-semver priority ladder); self-hosted instances via registries.gitlab_instance_host; scalar YAML anchor/alias resolution within include:

Many of the behaviors above are shared across several ecosystems rather than reimplemented per crate — see Cross-Ecosystem Features for the conventions and diagnostics that apply the same way everywhere they’re listed.