Dependency versions have no upper bound when `uv` is selected as packaging tool
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Da chiarire
- Stato di attività
- Tranquilla
- Stack tecnologico
- python
- Ambito
- build-system
Direzione di ricerca
Inizia leggendo l’issue #507, quindi esamina pyproject.toml, i file *requirements.txt e l’hook di cookiecutter che valorizza le versioni delle dipendenze. Confronta gli approcci disponibili e verifica che i progetti generati ricevano versioni delle dipendenze vincolate, preservando al contempo il comportamento dell’opzione mkdocs.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
The way we specify dependency versions in pyproject.toml for uv is like so:
[dependency-groups]
dev = [
"ruff>=VERSION",
"mypy>=VERSION",
"pre-commit>=VERSION",
"pytest>=VERSION",
"pytest-cov>=VERSION",
"pytest-mock>=VERSION",
]
# etc.
where VERSION is a placeholder value, filled in by our cookiecutter hook using values from the various *requirements.txt files. The problem is that there is no upper bound on these versions and no lock file included in the template, so users may end up with an incompatible version of one of these dependencies. The usual way to specify dep versions with uv is like so:
dependencies = [
"matplotlib<4.0.0,>=3.10.1",
# etc.
Assuming the package uses semver, this should reduce the chance of breakage, even if there's no lockfile.
When fixing this, we should bear in mind #507, which will give us the option of simplifying the template, including possibly by dropping the hook script altogether.
I see a few ways of going about this:
- We keep the
*requirements.txtfiles and hook as they are currently, even though the files won't end up in any generated project anymore. The reason for doing this would be so we can keep the templating inpyproject.tomlfile and still get version updates from dependabot. In this case, we will need to change the hook to specify version ranges in the form above (i.e. calculate what the next major version will be), which is annoying. - We drop these files and have a
pyproject.tomlfile without any templating in it, which dependabot will be able to parse and update directly. In this case, we will still probably want a hook to drop the unneeded doc dependencies when themkdocsoption is set to false. This will also be annoying, but probably less so than option 1.
I'm marking this as on hold for now because I think we should do #507 first. Alternatively, we could do this issue at the same time.
- Lingua principale
- Python
- Stelle
- 14
- Fork
- 8
- Merge medio
- 15m
- PR unite (30g)
- 1
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Nessuna guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ImperialCollegeLondon/python-template
-
question
Difficoltà 1/5 1-3 ore Idoneità per principianti 65/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
-
Update to use `uv init`Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
ImperialCollegeLondon/python-template#568 · 1 commento ·
-
Add all contributors configForse di nuovo libera @alexdewar l’ha presa 133 giorni fa e non c’è nessuna pull request aperta. Aperta
ImperialCollegeLondon/python-template#558 · 1 assegnatario ·
Tutte le issue di ImperialCollegeLondon/python-template
Issue simili
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
epam/ai-dial-quickapps-backend#628 ·
I maintainer di solito rispondono entro 2 giorni
-
0xlau.dev 已失效,切换成 timlau.meAperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 69/100
timqian/chinese-independent-blogs#2235 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
eclipse-score/coverage_tool#27 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
bojieli/ai-agent-book#1174 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
RedHatQE/mtv-api-tests#721 ·
I maintainer di solito rispondono entro 1 giorno