PRPM documentation
PRPM
The package manager for the PyReact ecosystem.
Create projects, install isolated dependencies, lock versions, and run scripts with a single tool.
Why PRPM?
PyReact projects are Python projects. PRPM builds on that ecosystem instead of creating an incompatible registry:
it uses the standard
pyproject.tomlas its manifest;resolves packages from PyPI, including
pyreact-framework;automatically creates an isolated
.venv;generates a reproducible
prpm.lock;provides a familiar experience for npm users;
remains compatible with
pip, build backends, and Python editors.
Installation
PRPM requires Python 3.9 or newer.
python -m pip install prpm
Install the development version directly from GitHub:
python -m pip install git+https://github.com/wanbnn/prpm.git
Set up a local development checkout:
git clone https://github.com/wanbnn/prpm.git
cd prpm
python -m pip install -e ".[dev]"
Quick start
Create and prepare a PyReact application:
prpm create my-app
cd my-app
prpm run dev
The command creates a complete SSR dashboard, installs pyreact-framework
inside .venv, and writes the lockfile. The generated project includes a
development server, interactive API, light and dark themes, static build, and
tests.
For an existing project:
git clone https://github.com/wanbnn/agenticflow.git
cd agenticflow
prpm install
prpm exec agentic-flow
PRPM reads the dependencies already declared in [project].dependencies.
Commands
Command |
Description |
|---|---|
|
Create and install a PyReact application |
|
Initialize a |
|
Resolve, install, and update |
|
Install exactly from the lockfile; ideal for CI |
|
Install and save a dependency |
|
Install and save a development dependency |
|
Remove a dependency |
|
Update all or selected dependencies |
|
List direct or all dependencies |
|
List or run scripts |
|
Run a binary inside |
|
Shortcut for the |
|
Query package metadata on PyPI |
|
Generate or validate the lockfile |
|
Store or remove a token from the keyring |
|
Show the active credential and key |
|
Generate, show, or rotate the Ed25519 key |
|
Build, validate, and sign a wheel and sdist |
|
Package and publish to PyPI |
|
Verify a local or published release |
|
Show the environment status |
Available aliases are i, rm, up, and ls.
Dependencies
Dependency specifiers follow Python standards:
prpm add httpx
prpm add "fastapi>=0.115,<1"
prpm add -D "pytest>=8"
prpm add "component @ git+https://github.com/user/component.git"
When no version is supplied, PRPM saves the minimum resolved version, such as
httpx>=0.28.1.
Scripts
Declare scripts in the manifest:
[tool.prpm.scripts]
dev = "pyreact dev"
build = "pyreact build"
test = "python -m pytest"
serve = ["python", "-m", "my_app"]
Run them without manually activating .venv:
prpm run build
prpm test -q
prpm exec python --version
Manifest and lockfile
The manifest remains a valid pyproject.toml:
[project]
name = "my-app"
version = "0.1.0"
requires-python = ">=3.9"
dependencies = ["pyreact-framework>=1.0.5"]
[project.optional-dependencies]
dev = ["pytest>=8"]
Commit prpm.lock to version control. It records the exact version, source, and
index-provided hashes for every package. In CI, use:
prpm install --frozen
prpm test
Frozen mode fails before installation if the manifest and lockfile differ.
Publishing packages
PRPM uses PyPI as its registry. Create a token at https://pypi.org/manage/account/token/ and sign in:
prpm login
prpm whoami
The token is entered without terminal echo and stored in the system keyring. It is never written to the project or passed on the command line. The first login also creates an Ed25519 identity:
prpm key show
prpm key rotate
Prepare and verify a release without publishing it:
prpm pack
prpm verify dist
The dist/ directory will contain the wheel, source distribution,
prpm-manifest.json, and prpm-manifest.sig. The manifest records SHA-256
hashes, sizes, dependencies, and the public key; the signature authenticates
that manifest.
Publish with:
prpm publish
PRPM rebuilds the artifacts, runs twine check, validates the signature,
uploads the wheel and sdist, and compares remote hashes through the PyPI API.
Use --no-build for an already packed release or --dry-run to validate the
entire flow without uploading.
TestPyPI is also supported:
prpm login --repository testpypi
prpm publish --repository testpypi
For CI, provide PRPM_PYPI_TOKEN or PRPM_TESTPYPI_TOKEN as a secret
environment variable. When no keyring is available, pack creates an ephemeral
Ed25519 identity for that release.
Verify any published package:
prpm verify prpm
prpm verify "prpm==0.3.0"
Remote verification compares files with PyPI SHA-256 values and validates every
wheel RECORD entry. PyPI remains the authority for maintainer and package-name
ownership.
Development
python -m pip install -e ".[dev]"
python -m pytest
python -m prpm --help
See CONTRIBUTING.md for the contribution workflow and the complete documentation.
License
MIT. See LICENSE.