Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Dependency versions have no upper bound when `uv` is selected as packaging tool

オープン
#529 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
35/100
issue の種類
バグ
明瞭さ
説明が足りない
活発さ
静か
技術スタック
python
領域
build-system

調査の方向性

まず issue #507 を読み、次に pyproject.toml、*requirements.txt ファイル、および依存関係のバージョンを設定する cookiecutter フックを調べます。利用可能なアプローチを比較し、生成されたプロジェクトに依存関係のバージョン範囲が設定されることを確認するとともに、mkdocs オプションの動作を維持します。

索引モデルが issue の本文から書いたものです。

説明

bug

The way we specify dependency versions in pyproject.toml for uv is like so:

[dependency-groups]
dev = [
    "ruff>=VERSION",
    "mypy>=VERSION",
    "pre-commit>=VERSION",
    "pytest>=VERSION",
    "pytest-cov>=VERSION",
    "pytest-mock>=VERSION",
]
# etc.

where VERSION is a placeholder value, filled in by our cookiecutter hook using values from the various *requirements.txt files. The problem is that there is no upper bound on these versions and no lock file included in the template, so users may end up with an incompatible version of one of these dependencies. The usual way to specify dep versions with uv is like so:

dependencies = [
    "matplotlib<4.0.0,>=3.10.1",
    # etc.

Assuming the package uses semver, this should reduce the chance of breakage, even if there's no lockfile.

When fixing this, we should bear in mind #507, which will give us the option of simplifying the template, including possibly by dropping the hook script altogether.

I see a few ways of going about this:

  1. We keep the *requirements.txt files and hook as they are currently, even though the files won't end up in any generated project anymore. The reason for doing this would be so we can keep the templating in pyproject.toml file and still get version updates from dependabot. In this case, we will need to change the hook to specify version ranges in the form above (i.e. calculate what the next major version will be), which is annoying.
  2. We drop these files and have a pyproject.toml file without any templating in it, which dependabot will be able to parse and update directly. In this case, we will still probably want a hook to drop the unneeded doc dependencies when the mkdocs option is set to false. This will also be annoying, but probably less so than option 1.

I'm marking this as on hold for now because I think we should do #507 first. Alternatively, we could do this issue at the same time.

主要言語
Python
スター
14
フォーク
8
平均マージ
15分
マージ済み PR(30日)
1

環境構築

  • Dockerfile・Docker Compose ファイルなし
  • プルリクエストのテンプレートあり
  • コントリビューションガイドなし

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

ImperialCollegeLondon/python-template のほかの issue

ImperialCollegeLondon/python-template の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。