pypa / pypa/setuptools

Setuptools thinks a package name with a dash in it is a name and version when checking for a dependency locally.

Open
#381 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug major
Dominant language
Python
Stars
2.9k
Forks
1.4k
Avg merge
1d 1h
Merged PRs (30d)
1

Description

Originally reported by: nicksloan (Bitbucket: nicksloan, GitHub: nicksloan)


See this gist: https://gist.github.com/nicksloan/48dead9a1fcb72d356c9

The install_requires are processed in reverse order, so it encounters requests-oauthlib first, it installs that, then when it encounters requests later on it does a local search and recognizes requests-oauthlib as if were requests==oauthlib-0.5. It is apparently reading the package name up to the first dash only, and assuming the rest is the version.

pip install . does not have the same problem.


Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the dependency order from the linked gist, with requests-oauthlib before requests, and inspect Setuptools' local dependency checking and name/version parsing. Done means a dashed package is not treated as the requested package with the remainder as its version; verify the reported install scenario no longer misidentifies the dependency.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
build-system
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.