openlibhums / openlibhums/janeway

Use "constraints.txt" for indirect dependencies

Open
#4,627 0 comments 0 reactions 1 assignee View on GitHub

@mauromsl is already working on this.

Since Sep 18, 2025.

Dominant language
Python
Stars
238
Forks
97
Avg merge
9d 1h
Merged PRs (30d)
8

Description

Sometimes we might need to update some package that is not a Janeway's direct dependency (e.g. if pip audit complains 🙂 ).

Using "constraints" (ala pip install -r requirement.txt -c constraints.txt) seems more appropriate for indirect dependencies, because constraints.txt does not trigger any installation, but only limits the version of a package.

However this reflects on any place where "requirements.txt" is used.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.