bcrypt
pypi package · declared by 27 of 2,343 sampled repositories · graph computed 2026-08-24
Counted from the runtime dependencies public repositories declare — not the resolved tree. A transitive dependency is a consequence; a declared one is a choice. Development dependencies are excluded because they repeat across every project in a language regardless of what is being built.
Declared with
ranked by association, not by count| Declared with | Repositories | vs chance |
|---|---|---|
| alembic | 9 of 2,343 | 0.61 |
| python-multipart | 14 of 2,343 | 0.57 |
| pyjwt | 8 of 2,343 | 0.54 |
| pydantic-settings | 11 of 2,343 | 0.47 |
| sqlalchemy | 8 of 2,343 | 0.47 |
| fastapi | 16 of 2,343 | 0.42 |
| uvicorn | 15 of 2,343 | 0.42 |
| pydantic | 13 of 2,343 | 0.30 |
Every pair above is counted from the same evidence: repo manifest.
Used instead
candidates · shares a neighbourhood and refuses to co-occurNo alternative measured. A pair qualifies only if it shares a neighbourhood and then fails to appear together against an expectation that it would — and almost everything that shares a neighbourhood does appear together. That is the test working, not a gap in the data: similarity alone would list this tool’s closest neighbours as alternatives, and most of them are things it is used with.