# Dependency notes for Gleam

`gleam.toml` lists the packages a project needs and the versions it accepts. It does not say why a package is there, why a range is held back, or what to run after it moves.

Pacmon keeps a note for each dependency in `.pacmon/gleam/DEPENDENCY-NOTES.md`, beside `gleam.toml`, and shows it on the dependency's line.

## What Pacmon reads

- **Manifest:** `gleam.toml`
- **Notes file:** `.pacmon/gleam/DEPENDENCY-NOTES.md`
- **Section heading:** the dependency key: `## gleam_stdlib`, `## gleeunit`

Pacmon reads direct keys in `[dependencies]` and `[dev_dependencies]` in `gleam.toml`, including version, Hex, Git and path declarations. `manifest.toml`, transitive packages and other tables are not read.

Pacmon never runs Gleam, so it needs no Gleam or Erlang installation.

## Example

```toml
[dependencies]
gleam_stdlib = ">= 0.44.0 and < 2.0.0"
wisp = ">= 1.2.0 and < 2.0.0"
mist = ">= 3.0.0 and < 4.0.0"

[dev_dependencies]
gleeunit = ">= 1.0.0 and < 2.0.0"
```

`.pacmon/gleam/DEPENDENCY-NOTES.md`:

```md
## wisp

Web framework for the HTTP API; mist serves it.

### Agent notes

- purpose: routing and middleware for the HTTP API
- bump-with: mist
- verify: `gleam test`
- verified: 1.2.0
```

The heading is the dependency's key in `gleam.toml`, under `[dependencies]` or `[dev_dependencies]` alike: `wisp = ">= 1.2.0 and < 2.0.0"` is `## wisp`.

## For AI coding agents

An agent reads a dependency's section before it adds, upgrades or removes it, and logs what it did under `### Agent notes`. See [the rules agents follow](https://pacmon.dev/agents/).
