3 ms·
The problem is that (just about) all python packages express their dependencies with a script called setup.py. To figure out the full transitive closure of depe
by cwp 8y ago
The problem is that (just about) all python packages express their dependencies with a script called setup.py. To figure out the full transitive closure of dependencies you have to walk the graph, downloading and executing setup.py scripts. First of all, that's slow.
But worse, setup.py is a python script with access to the full power of python. It can crash. It can be slow. It can loop forever. It can have dependencies of its own. It can require specific versions of python. It can download stuff from the internet. It can do anything.
If you wanted to implement something like npm for python, you'd have to convince all the python package maintainers to write and test package.json files for all their packages. Even if they were willing and enthusiastic about that, you'd have a chicken and egg problem because nobody could test a package.json until all their dependencies had them.
Python has a such a plethora of packaging tools because people keep trying to solve the problem by writing better code. But the real problem is lack metadata. Python will always have a lousy packaging ecosystem because it relies on setup.py.