bazel-contrib / bazel-contrib/rules_python

pip_parse: lockfile for build dependencies in repository rule

Offen
#1,325 9 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen
help wanted type: pip
Vorherrschende Sprache
Starlark
Sterne
688
Forks
721
Ø Merge
15 Std. 7 Min.
Gemergte PRs (30 T.)
76

Beschreibung

Since [PEP 518](https://peps.python.org/pep-0518/) projects can specify their build system requirements in their pyproject.toml file. Currently this is not included in the pip-compile and therefore can lead to non-reproducible issues. This happened in the wild today because pyyaml depends on cython but didn't pin its major version, so when cython pushed an incompatible version this broke if you were including it in bazel. One of the potential workarounds is to install the compatible cython version in the venv _before_ installing your requirements, which I also don't believe is possible. I believe supporting this would require pip-tools to also support this option, which is potentially implemented by https://github.com/jazzband/pip-tools/pull/1681

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by reviewing the pip_parse repository rule's current pip-compile flow and the referenced pip-tools pull request #1681. Determine how build-system requirements from pyproject.toml should be included, and consider the work complete when those dependencies are locked reproducibly for repository builds.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
build-system
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
32/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.