cryptography
pypi package · declared by 96 of 2,343 sampled repositories · graph computed 2026-08-24
Counted from the runtime dependencies public repositories declare — not the resolved tree. A transitive dependency is a consequence; a declared one is a choice. Development dependencies are excluded because they repeat across every project in a language regardless of what is being built.
Declared with
ranked by association, not by count| Declared with | Repositories | vs chance |
|---|---|---|
| pyjwt | 16 of 2,343 | 0.50 |
| apscheduler | 9 of 2,343 | 0.49 |
| sqlalchemy | 17 of 2,343 | 0.44 |
| aiosqlite | 10 of 2,343 | 0.43 |
| pypdf | 9 of 2,343 | 0.42 |
| starlette | 11 of 2,343 | 0.42 |
| fastapi | 39 of 2,343 | 0.42 |
| uvicorn | 36 of 2,343 | 0.41 |
| aiohttp | 17 of 2,343 | 0.39 |
| alembic | 9 of 2,343 | 0.38 |
| websockets | 12 of 2,343 | 0.37 |
| httpx | 30 of 2,343 | 0.36 |
| aiofiles | 10 of 2,343 | 0.35 |
| playwright | 9 of 2,343 | 0.35 |
| pydantic-settings | 17 of 2,343 | 0.35 |
| python-multipart | 15 of 2,343 | 0.34 |
| python-dotenv | 28 of 2,343 | 0.33 |
| pydantic | 34 of 2,343 | 0.29 |
| mcp | 12 of 2,343 | 0.26 |
| psutil | 9 of 2,343 | 0.25 |
Every pair above is counted from the same evidence: repo manifest.
Used instead
candidates · shares a neighbourhood and refuses to co-occurNo alternative measured. A pair qualifies only if it shares a neighbourhood and then fails to appear together against an expectation that it would — and almost everything that shares a neighbourhood does appear together. That is the test working, not a gap in the data: similarity alone would list this tool’s closest neighbours as alternatives, and most of them are things it is used with.