bazel-contrib / bazel-contrib/rules_python
pip_parse: lockfile for build dependencies in repository rule
- Ngôn ngữ chính
- Starlark
- Star
- 688
- Fork
- 721
- Merge trung bình
- 15 giờ 7 phút
- Pull request đã merge (30 ngày)
- 76
Mô tả
Since [PEP 518](https://peps.python.org/pep-0518/) projects can specify their build system requirements in their pyproject.toml file. Currently this is not included in the pip-compile and therefore can lead to non-reproducible issues. This happened in the wild today because pyyaml depends on cython but didn't pin its major version, so when cython pushed an incompatible version this broke if you were including it in bazel. One of the potential workarounds is to install the compatible cython version in the venv _before_ installing your requirements, which I also don't believe is possible. I believe supporting this would require pip-tools to also support this option, which is potentially implemented by https://github.com/jazzband/pip-tools/pull/1681
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu bằng cách xem xét quy trình pip-compile hiện tại của quy tắc repository pip_parse và pull request #1681 của pip-tools được tham chiếu. Xác định cách đưa các yêu cầu của hệ thống build từ pyproject.toml vào, và coi công việc là hoàn tất khi các dependency đó được khóa một cách có thể tái lập cho các bản build của repository.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- python
- Lĩnh vực
- build-system
- Loại issue
- Tính năng
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Cần làm rõ
- Mức phù hợp với người mới
- 32/100