bazel-contrib / bazel-contrib/rules_python

`pip.parse` should allow hiding transitive dependencies

Đang mở
#3,413 3 bình luận 2 reaction 0 người được giao Xem trên GitHub
help wanted
Ngôn ngữ chính
Starlark
Star
688
Fork
721
Merge trung bình
15 giờ 7 phút
Pull request đã merge (30 ngày)
76

Mô tả

# 🚀 feature request

### Relevant Rules

`pip.parse`

### Description

Given a `requirements.in` file containing only `foo==4.2.0` from which I create a lock file with content
```
foo==4.2.0 --hash=
dep_of_foo==1.33.7 --hash=
```

When using `pip.parse` to crate a hub `@pypi` from this lock file users can access all Python modules from the lock file. Concretely, `@pypi//foo` and `@pypi//dep_of_foo`.

I consider `dep_of_foo` an implementation detail which no user should depend on. When changing the version of `foo`, then `dep_of_foo` might vanish or change drastically as side effect. If I wanted users to access `dep_of_foo`, I would have added it to the `requirements.in` file to make it an explicit and desired direct dependency of my project.

It would be great if there were an option enforcing that transitive dependencies are not available to users.

### Describe the solution you'd like

Ideally `pip.parse` would offer an attribute `restrict_visibility_to` (or any other name) which takes a file list. Then, one could provide one or multiple `requirements.in` files to this attribute. `pip.parse` can then read those files, extract the Python module names and ensure only those are public targets in the pip hub.

The implementation would be easier if `restrict_visibility_to` takes a list of strings and the user explicitly states which Python modules should be public. However, I consider this inferior, as it increases the maintenance burden whenever changing the `requirements.in` files.

### Describe alternatives you've considered

I implemented the described behavior locally as a workspace rule, which creates a new hub with alias targets pointing to the hub created by `pip.parse`. It is trivial to do so, not much logic is required.

However, this means one has to teach people not to use the original hub created by `pip.parse`. Or one has to write yet another piece of custom code for a BUILD file checker ensuring this rule.
Overall, it would be much nicer if this behavior would be a feature of upstream `pip.parse`.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu từ quy tắc `pip.parse` và so sánh các đầu vào `requirements.in` với tệp lock được tạo và các đích của pip hub. Xem lại quy tắc workspace cục bộ và phương án thay thế bằng trình kiểm tra tệp BUILD được mô tả trong issue để hiểu ranh giới visibility dự kiến. Được coi là hoàn tất khi các dependency trực tiếp vẫn public, còn các dependency bắc cầu bị ẩn mà không cần các custom rule trùng lặp.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
build-system
Loại issue
Tính năng
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
45/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.