Skip to content

Supported projects

Capability Status
Node.js runtime Node 20 or later
TypeScript matching Supported: .ts, .tsx, .mts, .cts
JavaScript matching Supported: .js, .jsx, .mjs, .cjs
Python dependency detection Supported
Python source matching Not yet supported

Python files can be identified by the source walk, but no Python grammar or PyPI feed entry ships yet. A Python candidate produces a coverage warning instead of being guessed through a JavaScript matcher.

Ecosystem Files
npm package.json, package-lock.json, pnpm-lock.yaml, pnpm-workspace.yaml, yarn.lock
PyPI pyproject.toml, requirements.txt, poetry.lock, uv.lock

Emendant reports both direct and transitive dependencies during detection, but normal feed selection uses directly declared packages. npm package aliases are supported and matched under the local import name.

Declared workspaces are supported through:

  • workspaces in the root package.json;
  • packages in pnpm-workspace.yaml; and
  • [tool.uv.workspace] in pyproject.toml.

Each workspace is scanned separately so a package installed in one workspace is not attributed to code in another. Nested workspace declarations are not expanded.

The feed covers the AI SDKs:

Package Releases described
ai (Vercel AI SDK) 4.0.0, 5.0.0, 6.0.0, 7.0.0, 7.0.40, 7.0.50
openai 5.0.0, 7.5.0
@anthropic-ai/sdk 0.50.1, 0.72.1, 0.118.0, 0.122.0
langchain 0.3.0, 1.0.1, 1.0.3
@langchain/core 1.0.0, 1.1.25, 1.1.31
@google/genai 1.50.1, 2.8.0

emendant feed status prints the snapshot your machine holds, and emendant explain <change-id> prints the entry behind any single result, so the feed itself is always the exact answer to what is covered today. The SDK Changes pages describe what each covered release breaks, with the coverage table generated from the feed entry itself, and there is an RSS feed of them.

Every change cites a primary source pinned to the release it describes, and every entry is written from the published package rather than from a migration guide. That distinction is the whole of what severity means here: a guide that says a name was renamed, where the package kept the old name as a deprecated alias, describes a deprecation and not a break.

Coverage grows without a new release of the tool. New entries are published as signed snapshots, and emendant feed update picks them up. A repository is scanned only for changes that exist in the feed; Emendant does not invent findings for uncatalogued changes.

Three further packages are watched rather than described: @modelcontextprotocol/sdk, @openai/agents, and llamaindex. Watching a package means each new stable release is compared against the last one, so an entry appears when a release breaks something rather than as a backlog of old releases.

An API or SDK the feed does not cover yet can be requested. Requests are counted and are one of the things that decides what is curated next. Covering a package means reading its published releases and writing an entry for each breaking change, so a request is a signal rather than a queue position.

The source walk skips:

  • dependencies, build output, caches, virtual environments, coverage, and vendored directories;
  • paths excluded by committed .gitignore rules or emendant.json;
  • minified and bundled JavaScript;
  • files over 1,000,000 characters; and
  • extensions no current matcher can interpret.

See Known limitations for the precision trade-offs behind these boundaries.