Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Dependency versions have no upper bound when `uv` is selected as packaging tool

Aperta
#529 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Da chiarire
Stato di attività
Tranquilla
Stack tecnologico
python
Ambito
build-system

Direzione di ricerca

Inizia leggendo l’issue #507, quindi esamina pyproject.toml, i file *requirements.txt e l’hook di cookiecutter che valorizza le versioni delle dipendenze. Confronta gli approcci disponibili e verifica che i progetti generati ricevano versioni delle dipendenze vincolate, preservando al contempo il comportamento dell’opzione mkdocs.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug

The way we specify dependency versions in pyproject.toml for uv is like so:

[dependency-groups]
dev = [
    "ruff>=VERSION",
    "mypy>=VERSION",
    "pre-commit>=VERSION",
    "pytest>=VERSION",
    "pytest-cov>=VERSION",
    "pytest-mock>=VERSION",
]
# etc.

where VERSION is a placeholder value, filled in by our cookiecutter hook using values from the various *requirements.txt files. The problem is that there is no upper bound on these versions and no lock file included in the template, so users may end up with an incompatible version of one of these dependencies. The usual way to specify dep versions with uv is like so:

dependencies = [
    "matplotlib<4.0.0,>=3.10.1",
    # etc.

Assuming the package uses semver, this should reduce the chance of breakage, even if there's no lockfile.

When fixing this, we should bear in mind #507, which will give us the option of simplifying the template, including possibly by dropping the hook script altogether.

I see a few ways of going about this:

  1. We keep the *requirements.txt files and hook as they are currently, even though the files won't end up in any generated project anymore. The reason for doing this would be so we can keep the templating in pyproject.toml file and still get version updates from dependabot. In this case, we will need to change the hook to specify version ranges in the form above (i.e. calculate what the next major version will be), which is annoying.
  2. We drop these files and have a pyproject.toml file without any templating in it, which dependabot will be able to parse and update directly. In this case, we will still probably want a hook to drop the unneeded doc dependencies when the mkdocs option is set to false. This will also be annoying, but probably less so than option 1.

I'm marking this as on hold for now because I think we should do #507 first. Alternatively, we could do this issue at the same time.

Lingua principale
Python
Stelle
14
Fork
8
Merge medio
15m
PR unite (30g)
1

Preparare l'ambiente

  • Nessun Dockerfile né file Docker Compose
  • Ha un modello di pull request
  • Nessuna guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di ImperialCollegeLondon/python-template

Tutte le issue di ImperialCollegeLondon/python-template

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.