Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

`pip.parse` drops extras declared on the wheel's dependency (`package[extra]`)

Open
#4,168 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
72/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
python
Domain
build-system

Research direction

Start in python/private/pypi/pep508_deps.bzl, then read pep508_requirement.bzl to trace how extras are parsed and resolved for transitive requirements. Reproduce with fastmcp==4.0.5 using the documented uv and Bazel commands. Done means the fastmcp_slim target preserves the client and server extras and its gated dependencies are available in the resulting importable environment.

Written by the indexing model from the issue text.

Description

🐞 bug report

Affected Rule

pip.parse

Is this a regression?

Not really, it's caused by upgrading fastmcp from v3 to v4

Description

fastmcp==4.0.5 declares fastmcp-slim[client,server]==4.0.5 unconditionally
in its Requires-Dist, and fastmcp-slim gates its client and server
dependencies (httpx2, authlib, mcp, starlette, and others) behind those
extras. When fastmcp is pulled in through pip.parse, rules_python does not
enable the client and server extras on the fastmcp_slim target, so those
gated dependencies are never wired into the dependency graph. Depending on
@pypi//fastmcp therefore produces a different importable environment than
pip install fastmcp: import fastmcp.client fails at runtime with
ModuleNotFoundError: No module named 'httpx2', even though httpx2 and the
other extra dependencies are pinned in the lock and exist as @pypi//… targets.

The cause is in python/private/pypi/pep508_deps.bzl. The
fastmcp-slim[client,server] edge is parsed into a requirement with
.name == "fastmcp-slim" and .extras == ["client", "server"]
(pep508_requirement.bzl), but _resolve_extras() only consults req.extras
for self-edges (if req.name != self_name: continue), and the dependency label
is built from req.name alone, so the [client,server] qualifier is discarded.
Whether a package's extra == '...' dependencies are wired is then decided
solely by the extras passed to that package's own whl_library, which is
populated from how the package appears as a requirement line in the lock.
fastmcp-slim appears only as a plain transitive pin with no extras, so its
whl_library receives extras = [] and the client and server dependencies are
dropped.

🔬 Minimal Reproduction

uv add fastmcp==4.0.5
uv export --format requirements.txt > ./requirements.txt
bazel build //...

🔥 Exception or Error

ImportError: FastMCP client support is not installed. Install `fastmcp` or `fastmcp-slim[client]`.

🌍 Your Environment

Operating System:

ubuntu 24.04

Output of bazel version:

Build label: 8.6.0
Build target: @@//src/main/java/com/google/devtools/build/lib/bazel:BazelServer
Build time: Thu Feb 26 19:55:20 2026 (1772135720)
Build timestamp: 1772135720
Build timestamp as int: 1772135720

Rules_python version:

1.9.2

Anything else relevant?

Dominant language
Starlark
Stars
690
Forks
722
Avg merge
1d 55m
Merged PRs (30d)
38

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from bazel-contrib/rules_python

All issues in bazel-contrib/rules_python

Similar issues

More Build System issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.