4 ms·
My problem with pip-tools is this: # pip-tools dependencies dependencies = [ # direct dependencies "build >= 1.0.0", "click >= 8", "pip >= 22.2",
by sealedservant 2y ago
My problem with pip-tools is this:
# pip-tools dependencies
dependencies = [
# direct dependencies
"build >= 1.0.0",
"click >= 8",
"pip >= 22.2",
"pyproject_hooks",
"tomli; python_version < '3.11'",
# indirect dependencies
"setuptools", # typically needed when pip-tools invokes setup.py
"wheel", # pip plugin needed by pip-tools
]
pip is nice since it comes out of the box with Python. setuptools used to but now it's gone.
The dependency explosion is a huge problem for a lot of people trying to lockdown the security and maintainability of their codebases. I think that's why a lot of people are rallying around Astral's projects like uv and ruff... they do so many things and they do them well.
- nrclark 2y agoThe nice thing about my approach is that pip-tools is only needed when modifying your requirements, and it also lives in a separate venv/requirements.txt from the dependencies you actually care about. So yes: you need those dependencies in a development context, if you're actively modifying your Python requirements. But they don't make their way into your production requirements.txt, and don't need to be installed anywhere other than a short-lived venv.