Dependency versions have no upper bound when `uv` is selected as packaging tool
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- python
- Lĩnh vực
- build-system
Hướng nghiên cứu
Bắt đầu bằng việc đọc issue #507, sau đó kiểm tra pyproject.toml, các tệp *requirements.txt và hook cookiecutter dùng để điền phiên bản dependency. So sánh các cách tiếp cận hiện có và xác minh rằng các project được tạo nhận các phiên bản dependency có giới hạn, đồng thời vẫn giữ nguyên hành vi của tùy chọn mkdocs.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
The way we specify dependency versions in pyproject.toml for uv is like so:
[dependency-groups]
dev = [
"ruff>=VERSION",
"mypy>=VERSION",
"pre-commit>=VERSION",
"pytest>=VERSION",
"pytest-cov>=VERSION",
"pytest-mock>=VERSION",
]
# etc.
where VERSION is a placeholder value, filled in by our cookiecutter hook using values from the various *requirements.txt files. The problem is that there is no upper bound on these versions and no lock file included in the template, so users may end up with an incompatible version of one of these dependencies. The usual way to specify dep versions with uv is like so:
dependencies = [
"matplotlib<4.0.0,>=3.10.1",
# etc.
Assuming the package uses semver, this should reduce the chance of breakage, even if there's no lockfile.
When fixing this, we should bear in mind #507, which will give us the option of simplifying the template, including possibly by dropping the hook script altogether.
I see a few ways of going about this:
- We keep the
*requirements.txtfiles and hook as they are currently, even though the files won't end up in any generated project anymore. The reason for doing this would be so we can keep the templating inpyproject.tomlfile and still get version updates from dependabot. In this case, we will need to change the hook to specify version ranges in the form above (i.e. calculate what the next major version will be), which is annoying. - We drop these files and have a
pyproject.tomlfile without any templating in it, which dependabot will be able to parse and update directly. In this case, we will still probably want a hook to drop the unneeded doc dependencies when themkdocsoption is set to false. This will also be annoying, but probably less so than option 1.
I'm marking this as on hold for now because I think we should do #507 first. Alternatively, we could do this issue at the same time.
- Ngôn ngữ chính
- Python
- Star
- 14
- Fork
- 8
- Merge trung bình
- 15 phút
- Pull request đã merge (30 ngày)
- 1
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Không có hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của ImperialCollegeLondon/python-template
-
question
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 65/100
-
Make build backend configurableĐang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
-
Update to use `uv init`Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
ImperialCollegeLondon/python-template#568 · 1 bình luận ·
-
Add all contributors configCó thể làm lại được @alexdewar đã nhận 133 ngày trước và không có pull request nào đang mở. Đang mở
ImperialCollegeLondon/python-template#558 · 1 người được giao ·
Tất cả issue của ImperialCollegeLondon/python-template
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 1 ngày
-
SR_SECURITY_DESCRIPTOR.fromString drops the SACL when no DACL is presentCó thể đã có người làm @paul7436 đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
equinor/fmu-sumo-uploader#302 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
modelscope/evalscope#1821 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Sanity on ansible-core devel fails: ignore-2.23.txt references the removed import-3.9 testCó thể đã có người làm @yurnov đã nhận hôm nay. Đang mởneeds_triage
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 91/100
ansible-collections/kubernetes.core#1275 ·
Maintainer thường phản hồi trong vòng 1 ngày