Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Dependency versions have no upper bound when `uv` is selected as packaging tool

Đang mở
#529 2 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Lỗi
Độ rõ ràng
Cần làm rõ
Mức độ hoạt động
Ít trao đổi
Công nghệ
python
Lĩnh vực
build-system

Hướng nghiên cứu

Bắt đầu bằng việc đọc issue #507, sau đó kiểm tra pyproject.toml, các tệp *requirements.txt và hook cookiecutter dùng để điền phiên bản dependency. So sánh các cách tiếp cận hiện có và xác minh rằng các project được tạo nhận các phiên bản dependency có giới hạn, đồng thời vẫn giữ nguyên hành vi của tùy chọn mkdocs.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug

The way we specify dependency versions in pyproject.toml for uv is like so:

[dependency-groups]
dev = [
    "ruff>=VERSION",
    "mypy>=VERSION",
    "pre-commit>=VERSION",
    "pytest>=VERSION",
    "pytest-cov>=VERSION",
    "pytest-mock>=VERSION",
]
# etc.

where VERSION is a placeholder value, filled in by our cookiecutter hook using values from the various *requirements.txt files. The problem is that there is no upper bound on these versions and no lock file included in the template, so users may end up with an incompatible version of one of these dependencies. The usual way to specify dep versions with uv is like so:

dependencies = [
    "matplotlib<4.0.0,>=3.10.1",
    # etc.

Assuming the package uses semver, this should reduce the chance of breakage, even if there's no lockfile.

When fixing this, we should bear in mind #507, which will give us the option of simplifying the template, including possibly by dropping the hook script altogether.

I see a few ways of going about this:

  1. We keep the *requirements.txt files and hook as they are currently, even though the files won't end up in any generated project anymore. The reason for doing this would be so we can keep the templating in pyproject.toml file and still get version updates from dependabot. In this case, we will need to change the hook to specify version ranges in the form above (i.e. calculate what the next major version will be), which is annoying.
  2. We drop these files and have a pyproject.toml file without any templating in it, which dependabot will be able to parse and update directly. In this case, we will still probably want a hook to drop the unneeded doc dependencies when the mkdocs option is set to false. This will also be annoying, but probably less so than option 1.

I'm marking this as on hold for now because I think we should do #507 first. Alternatively, we could do this issue at the same time.

Ngôn ngữ chính
Python
Star
14
Fork
8
Merge trung bình
15 phút
Pull request đã merge (30 ngày)
1

Chuẩn bị môi trường

  • Không có Dockerfile hay tệp Docker Compose
  • Có mẫu pull request
  • Không có hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của ImperialCollegeLondon/python-template

Tất cả issue của ImperialCollegeLondon/python-template

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.